Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-3014

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2008-3014
Last Modified 07 Mar 2011 10:10:05
Published 10 Sep 2008 09:11:47
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-3014

Summary

Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed WMF image file that triggers improper memory allocation, aka "GDI+ WMF Buffer Overrun Vulnerability."

Vulnerable Systems

Operating System

  • Microsoft Server 2003

  • Microsoft Windows-nt Vista

  • Microsoft Windows-nt Xp

Application

  • Microsoft Digital Image Suite 2006

  • Microsoft Forefront Client Security 1.0

  • Microsoft Internet Explorer 6

  • Microsoft Office 2003

  • Microsoft Office 2007

  • Microsoft Office Powerpoint Viewer 2003

  • Microsoft Office Xp

  • Microsoft Report Viewer 2005

  • Microsoft Report Viewer 2008

  • Microsoft Server 2008

  • Microsoft Sql Server 2005

  • Microsoft Sql Server Reporting Services 2000

  • Microsoft Visio 2002

  • Microsoft Works 8.0


References

CERT - TA08-253A

VUPEN - ADV-2008-2696

VUPEN - ADV-2008-2520

SECTRACK - 1020837

BID - 31021

MS - MS08-052

SECUNIA - 32154

HP - SSRT080133

HP - HPSBST02372

Related Patches

WinZip 11.2 SR-1 (Update) (See Notes) (Rev 2)


Last Updated: 27 May 2016 10:49:54