Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-3013

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2008-3013
Last Modified 18 Oct 2011 12:00:00
Published 10 Sep 2008 09:11:47
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-3013

Summary

gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed GIF image file containing many extension markers for graphic control extensions and subsequent unknown labels, aka "GDI+ GIF Parsing Vulnerability."

Vulnerable Systems

Operating System

  • Microsoft Windows Server 2008 -

  • Microsoft Windows Vista

  • Microsoft Windows Xp

Application

  • Microsoft Digital Image Suite 2006

  • Microsoft Forefront Client Security 1.0

  • Microsoft Ie 6

  • Microsoft Office 2003

  • Microsoft Office 2007

  • Microsoft Office Xp

  • Microsoft Powerpoint Viewer 2003

  • Microsoft Report Viewer 2005

  • Microsoft Report Viewer 2008

  • Microsoft Sql Server 2005

  • Microsoft Sql Server Reporting Services 2000

  • Microsoft Visio 2002

  • Microsoft Works 8


References

CERT - TA08-253A

MISC - http://www.zerodayinitiative.com/advisories/ZDI-08-056/

MISC - http://www.zerodayinitiative.com/advisories/ZDI-08-056

VUPEN - ADV-2008-2696

VUPEN - ADV-2008-2520

SECTRACK - 1020836

BID - 31020

BUGTRAQ - 20080909 ZDI-08-056: Microsoft Windows GDI+ GIF Parsing Code Execution Vulnerability

MS - MS08-052

SECUNIA - 32154

HP - SSRT080133

MISC - http://ifsec.blogspot.com/2008/09/windows-gdi-gif-memory-corruption.html

HP - HPSBST02372

Related Patches

WinZip 11.2 SR-1 (Update) (See Notes) (Rev 2)


Last Updated: 27 May 2016 10:49:54