MEDIUM · 5.0

CVE-2004-1305

The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame num...

Vulnerability Description

The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
NortelIp Softphone 2050All versions
NortelMedia Communication Server 51003.0
NortelMedia Communication Server 52003.0
NortelMedia Processing ServerAll versions
NortelPeriphonicsAll versions
NortelSymposium AgentAll versions
NortelSymposium Network Control CenterAll versions
NortelSymposium Tapi Service ProviderAll versions
NortelSymposium Web Centre PortalAll versions
NortelSymposium Web ClientAll versions
NortelSymposium Call Center ServerAll versions
NortelSymposium Express Call CenterAll versions
MicrosoftWindows 2000All versions
MicrosoftWindows 2003 Serverenterprise
MicrosoftWindows 98All versions
MicrosoftWindows 98SeAll versions
MicrosoftWindows MeAll versions
MicrosoftWindows Nt4.0
MicrosoftWindows XpAll versions

References

FAQ

What is CVE-2004-1305?

CVE-2004-1305 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame num...

How severe is CVE-2004-1305?

CVE-2004-1305 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-1305?

Check the references section above for vendor advisories and patch information. Affected products include: Nortel Ip Softphone 2050, Nortel Media Communication Server 5100, Nortel Media Communication Server 5200, Nortel Media Processing Server, Nortel Periphonics.