RULE(RULE ID:315803)

Rule General Information
Release Date: 2015-01-06
Rule Name: Microsoft JPEG Processing Buffer Overrun Vulnerability -2 (CVE-2004-0200)
Severity:
CVE ID:
Rule Protection Details
Description: Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
Impact: An attacker can execute arbitrary code in the context of the currently logged-in user. Failed exploit may cause denial-of-service attack.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:ms04-028
Solutions
Microsoft has released a patch MS04-028 to eliminate the vulnerability. The patch can be downloaded at http://www.microsoft.com/technet/security/bulletin/ms04-028.asp