Vulnerability Description
The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in Explorer) via a WAV file with an invalid file header whose fmt chunk length is set to 0xFFFFFFFF.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows Xp | All versions |
References
- http://marc.info/?l=bugtraq&m=109846319313443&w=2
- http://securitytracker.com/id?1011880
- http://www.hexview.com/docs/20041021-1.txtExploitVendor Advisory
- http://www.osvdb.org/11053
- http://www.securityfocus.com/bid/11503ExploitVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17864
- http://marc.info/?l=bugtraq&m=109846319313443&w=2
- http://securitytracker.com/id?1011880
- http://www.hexview.com/docs/20041021-1.txtExploitVendor Advisory
- http://www.osvdb.org/11053
- http://www.securityfocus.com/bid/11503ExploitVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17864
FAQ
What is CVE-2004-1623?
CVE-2004-1623 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in Explorer) via a WAV file with an invalid file header whose fmt chunk length is se...
How severe is CVE-2004-1623?
CVE-2004-1623 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1623?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows Xp.