Oval Definition:
oval:org.mitre.oval:def:8429
Revision Date
:
2010-03-22
Version
:
42
Title
:
MS Paint Integer Overflow Vulnerability
Description
:
Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."
Family
:
windows
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2010-0028
Platform(s)
:
Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows XP
Product(s)
:
Definition Synopsis
Vulnerable Microsoft Windows 2000 SP4 or later
Microsoft Windows 2000 SP4 or later is installed
AND
the version of Mspaint.exe is less than 5.0.2195.7368
OR
Vulnerable Microsoft Windows XP (x86) SP2
Microsoft Windows XP (x86) SP2 is installed
AND
the version of Mspaint.exe is less than 5.1.2600.3660
OR
Vulnerable Microsoft Windows XP (x86) SP3
Microsoft Windows XP (x86) SP3 is installed
AND
the version of Mspaint.exe is less than 5.1.2600.5918
OR
Vulnerable Microsoft Windows XP x64 SP2, Server 2003 x86/x64/ia64 SP2
Microsoft Windows XP x64 Edition SP2 is installed
OR
Microsoft Windows Server 2003 SP2 (x64) is installed
OR
Microsoft Windows Server 2003 SP2 (x86) is installed
OR
Microsoft Windows Server 2003 (ia64) SP2 is installed
AND
the version of Mspaint.exe is less than 5.2.3790.4638
BACK