Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-3012

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2008-3012
Last Modified 07 Mar 2011 10:10:05
Published 10 Sep 2008 09:11:47
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-3012

Summary

gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 does not properly perform memory allocation, which allows remote attackers to execute arbitrary code via a malformed EMF image file, aka "GDI+ EMF Memory Corruption Vulnerability."

Vulnerable Systems

Operating System

  • Microsoft Office System

  • Microsoft Windows 2003 Server

  • Microsoft Windows-nt Vista

  • Microsoft Windows-nt Xp

Application

  • Microsoft Digital Image Suite 2006

  • Microsoft Forefront Client Security 1.0

  • Microsoft Internet Explorer 6

  • Microsoft Office 2003

  • Microsoft Office Powerpoint Viewer 2003

  • Microsoft Office Xp

  • Microsoft Report Viewer 2005

  • Microsoft Report Viewer 2008

  • Microsoft Server 2008

  • Microsoft Sql Server 2005

  • Microsoft Sql Server Reporting Services 2000

  • Microsoft Visio 2002

  • Microsoft Works 8.0


References

CERT - TA08-253A

MS - MS08-052

VUPEN - ADV-2008-2696

VUPEN - ADV-2008-2520

SECTRACK - 1020835

BID - 31019

SECUNIA - 32154

HP - HPSBST02372

HP - SSRT080133

Related Patches

WinZip 11.2 SR-1 (Update) (See Notes) (Rev 2)


Last Updated: 27 May 2016 10:49:54