This application requires Javascript for optimal performance.

MS.CMM.ICC.Profile.Buffer.Overflow

Release Date

Jul 14, 2005

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt to exploit a buffer overflow vulnerability in the color management module ICC (International Color Consortium) profile of
Microsoft Windows.

This issue is caused by an error when the vulnerable software handles a malfromed ICC profile file.It may allow remote attackers to execute arbitrary code on vulnerable systems.


Affected Products

All releases of:
Microsoft Windows 2000 SP4
Windows XP SP2
Windows 2003 SP1
Windows 98
and all earlier service packs.
Nortel Networks Centrex IP Client Manager.

Recommended Actions

Refer to the vendor's web site for suggest workaround.
http://www.microsoft.com/technet/security/Bulletin/MS05-036.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2005-1219

Reference/s

http://www.securityfocus.com/bid/14214 (BugTraq)
http://technet.microsoft.com/en-us/security/bulletin/MS05-036.mspx (MS-ID)

Reference: VID-10226