Microsoft DirectWrite Unicode Character Processing Flaw Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1026794 |
|
SecurityTracker URL: http://securitytracker.com/id/1026794
|
|
CVE Reference:
CVE-2012-0156
(Links to External Site)
|
Date: Mar 13 2012
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
|
Description:
A vulnerability was reported in Microsoft DirectWrite. A remote user can cause denial of service conditions.
A user that can cause DirectWrite to render a specially crafted sequence of Unicode characters can cause the application using DirectWrite to crash.
This can be exploited, for example, by a remote user sending specially crafted characters via Windows Live Messenger to cause the target user's Windows Live Messenger application to crash.
Khaled M. Salameh reported this vulnerability.
|
Impact:
A remote user can cause an application using DirectWrite to crash.
|
Solution:
The vendor has issued the following fixes:
Windows Vista Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=7da5b341-6a6f-46de-8d01-448da38e9908
Windows Vista x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=1ba25d9c-0fef-471f-8e30-045fe9586a9c
Windows Server 2008 for 32-bit Systems Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=45a4784e-5051-4628-9a19-d53f30c1fdf3
Windows Server 2008 for x64-based Systems Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=503cb9c0-d6db-4deb-a555-67af0b25739b
Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=f3a14012-38ae-490e-a48e-7c851f82a7e6
Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=760b5aa4-4e65-4ff1-9ae2-771234803bf0
Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=86095b20-5869-4b55-8777-ee0af82aaf37
Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=dc5c336f-329c-4a56-8b24-555e3c8afd50
A restart may be required.
The Microsoft advisory is available at:
http://technet.microsoft.com/en-us/security/bulletin/ms12-019
|
Vendor URL: technet.microsoft.com/en-us/security/bulletin/ms12-019 (Links to External Site)
|
Cause:
Access control error, State error
|
Underlying OS:
Windows (2008), Windows (Vista)
|
|
Message History:
None.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|