Oval Definition:oval:org.mitre.oval:def:1530
Revision Date:2011-05-16Version:48
Title:Windows XP HtmlHelp Heap Overflow
Description:Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2004-0201
Platform(s):Microsoft Windows XP
Product(s):HTML Help Facility
Definition Synopsis
  • Software section
  • the version of itss.dll is less than 5.2.3790.185
  • AND NOT the patch kb840315 is installed
  • AND Windows XP (sp1 or earlier) is installed
  • Windows XP is installed
  • AND NOT Win2K/XP/2003 service pack 2 (or later) is installed
  • AND Configuration section
  • NOT HTML Help is registered
  • BACK