what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Venustech AD-Lab Advisory 2004.5

Venustech AD-Lab Advisory 2004.5
Posted Dec 31, 2004
Authored by FlashSky, Bejing Venustech

Venustech AD-Lab Advisory AD_LAB-04005 - Parsing a specially crafted ANI file causes the windows kernel to crash or stop to work properly. An attacker can crash or freeze a target system if he sends a specially crafted ANI file within an HTML page or within an Email. Vulnerable: Windows NT, Windows 2000 SP0, Windows 2000 SP1, Windows 2000 SP2, Windows 2000 SP3, Windows 2000 SP4, Windows XP SP0, Windows XP SP1, Windows 2003.

tags | advisory, kernel
systems | windows
SHA-256 | a4b61c9f9acb50b67f793629552a1104d23cf0c1bf9143acaaeb455b74faf2df

Venustech AD-Lab Advisory 2004.5

Change Mirror Download


[Security Advisory]


Advisory: [AD_LAB-04005]Microsoft Windows Kernel ANI File Parsing Crash and Dos Vulnerability
Class: Design Error
DATE:12/20/2004
Remote: Yes

Vulnerable:
Windows NT
Windows 2000 SP0
Windows 2000 SP1
Windows 2000 SP2
Windows 2000 SP3
Windows 2000 SP4
Windows XP SP0
Windows XP SP1
Windows 2003
Not vulnerable:
Windows XP SP2
Vendor:
www.microsoft.com


I.DESCRIPTION:
-------------

Parsing a specially crafted ANI file causes the windows kernel to crash or stop to work
properly. An attacker can crash or freeze a target system if he sends a specially crafted
ANI file within an HTML page or within an Email.

II.DETAILS:
----------

ANI stands for Windows Animated Cursor and manages many images frames. Two vulnerabilities
exist in the Windows kernel when it parses ANI files.

A first vulnerability exists because there is no proper check of the frame number set in the
ANI file header. If the Windows kernel try to parse the ANI file (offset 0x78 in the ANI
file header) and the frame number is set to 0, the kernel will calculate a wrong address to
access and then crash.

A second vulnerability exists because there is (again) no proper check of the rate number
set in the ANI file header. Setting this number to 0 causes the windows kernel to use up to
all of the system resources and then freeze.

More details and POC at https://www.xfocus.net/flashsky/icoExp/index.html

III.CREDIT:
----------

Flashsky(fangxing@venustech.com.cn;flashsky@xfocus.org) discovery this vuln:)
Vulnerability analysis and advisory by Flashsky and icbm.
Special thanks to "Fengshou" project members and all Venustech AD-Lab guys:P

V.DISCLAIMS:
-----------

The information in this bulletin is provided "AS IS" without warranty of any
kind. In no event shall we be liable for any damages whatsoever including direct,
indirect, incidental, consequential, loss of business profits or special damages.

Copyright 1996-2004 VENUSTECH. All Rights Reserved. Terms of use.

VENUSTECH Security Lab
VENUSTECH INFORMATION TECHNOLOGY CO.,LTD(https://www.venustech.com.cn)

Security
Trusted {Solution} Provider
Service
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    17 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close