CVE-2010-1098

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
24/03/2010
Last modified:
14/02/2024

Description

The ANI parser in Microsoft Windows before 7 on the x86 platform, as used in Internet Explorer and other applications, allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted biClrUsed value in the BITMAPINFO header of a .ANI file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:microsoft:windows_vista:*:*:x86:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:x86:*:*:*:*:*