CNCVE编号:CNCVE-20020074 CVE编号: 安全级别:中 漏洞中文描述: Microsoft IE和Outlook Express在处理畸形的嵌入于网页中的图片、HTML电子邮件和电子邮件附件里的XBM图形文件时会崩溃。这是由于对XBM文件的尺寸检查不充分的结果。MSIE基于(或部分的基于)指定的宽度和长度来分配内存存储图形文件。 攻击者可能利用这一点来指定一个过大尺寸值,这将导致系统内存耗尽或访问错误。其他依赖于IE的软件在处理畸形的XBM文件时也有可能崩溃。 漏洞英文描述: Microsoft Internet Explorer and Outlook Express crash when handling malformed XBM image files in webpages, HTML e-mail, or as an e-mail attachment. This is believed to be the result of insufficient checking of the content in XBM files. MSIE allocates memory to store the image based (partly) on the width and height specified. It may be possible for attackers to specify excessive values, resulting in exhaustion of system memory or access violation errors. Other software which relies upon Internet Explorer may also crash when handling malformed XBM files. 漏洞参考: http://online.securityfocus.com/bid/4653/info/ 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误