Microsoft Internet Explorer and Outlook Express crash when handling malformed XBM image files in webpages, HTML e-mail, or as an e-mail attachment. This is believed to be the result of insufficient checking of the content in XBM files. MSIE allocates memory to store the image based (partly) on the width and height specified. It may be possible for attackers to specify excessive values, resulting in exhaustion of system memory or access violation errors. Other software which relies upon Internet Explorer may also crash when handling malformed XBM files.
Microsoft Internet Explorer and Outlook Express crash when handling malformed XBM image files in webpages, HTML e-mail, or as an e-mail attachment. This is believed to be the result of insufficient checking of the content in XBM files. MSIE allocates memory to store the image based (partly) on the width and height specified. It may be possible for attackers to specify excessive values, resulting in exhaustion of system memory or access violation errors. Other software which relies upon Internet Explorer may also crash when handling malformed XBM files.