imPC@ndo IT

Tracker / CVE-2004-1305

CVE-2004-1305

Medium 5.0

The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.

Affected products and versions

microsoft windows_2000
microsoft windows_2003_server
microsoft windows_98
microsoft windows_98se
microsoft windows_me
microsoft windows_nt
microsoft windows_xp
nortel ip_softphone_2050
nortel media_communication_server_5100
nortel media_communication_server_5200
nortel media_processing_server
nortel periphonics
nortel symposium_agent
nortel symposium_call_center_server
nortel symposium_express_call_center
nortel symposium_network_control_center
nortel symposium_tapi_service_provider
nortel symposium_web_centre_portal
nortel symposium_web_client

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References