Microsoft GDI+ PNG File Processing 远程代码执行漏洞 CVE-2009-2501 CNNVD-200910-213

9.3 AV AC AU C I A
发布: 2009-10-14
修订: 2023-12-07

Microsoft Internet Explorer 6 SP1, Windows XP SP2和SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1和SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold和SP3, Office Excel Viewer 2003 Gold 和SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1,以及SP2, Word的微软Office文件格式兼容套装, Excel, 和PowerPoint 2007 File Formats SP1 和SP2, Expression Web, Expression Web 2, Groove 2007 Gold 和SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 和 SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold 和 SP1,和Forefront Client Security 1.0版本的GDI+允许远程攻击者执行任意代码可以借助特制的PNG图像文件中存在堆缓冲区溢出。该漏洞又称\"GDI+ PNG Heap Overflow漏洞\"。

0%
暂无可用Exp或PoC
当前有58条受影响产品信息