Description: Multiple vulnerabilities have been reported in various Microsoft products, which can be exploited by malicious people to compromise a vulnerable system.
1) An error in the GDI+ subsystem when handling gradient sizes can be exploited to cause a heap-based buffer overflow via a specially crafted file.
2) An error in the GDI+ subsystem when parsing EMF files can be exploited to cause memory corruption via a specially crafted EMF image file.
3) An error in the GDI+ subsystem when parsing records in GIF images can be exploited via a GIF image file containing a specially crafted graphic control extension.
4) An error in the GDI+ subsystem when parsing WMF files can be exploited to cause a buffer overflow via a specially crafted WMF image file.
5) An integer overflow in the GDI+ subsystem when parsing BMP file headers can be exploited to cause a buffer overflow via a BMP image file containing a specially crafted BitMapInfoHeader.
Successful exploitation of the vulnerabilities may allow execution of arbitrary code.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.