Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-3015

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2008-3015
Last Modified 12 Oct 2011 12:00:00
Published 10 Sep 2008 09:11:47
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-3015

Summary

Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a BMP image file with a malformed BitMapInfoHeader that triggers a buffer overflow, aka "GDI+ BMP Integer Overflow Vulnerability."

Vulnerable Systems

Application

  • Microsoft Digital Image Suite 2006

  • Microsoft Forefront Client Security 1.0

  • Microsoft Office 2003

  • Microsoft Office 2007

  • Microsoft Office Powerpoint Viewer 2003

  • Microsoft Office Xp

  • Microsoft Report Viewer 2005

  • Microsoft Report Viewer 2008

  • Microsoft Sql Server 2005

  • Microsoft Sql Server Reporting Services 2000

  • Microsoft Visio 2002

  • Microsoft Works 8.0


References

CERT - TA08-253A

MS - MS08-052

MISC - http://www.zerodayinitiative.com/advisories/ZDI-08-055

VUPEN - ADV-2008-2696

VUPEN - ADV-2008-2520

SECTRACK - 1020838

BID - 31022

BUGTRAQ - 20080909 ZDI-08-055: Microsoft Windows GDI+ BMP Parsing Code Execution Vulnerability

MILW0RM - 6716

MILW0RM - 6619

MISC - http://www.evilfingers.com/patchTuesday/MS08_052_GDI+_Vulnerability_ver2.txt

MISC - http://www.evilfingers.com/patchTuesday/MS08_052_GDI+_Vulnerability.txt

SECUNIA - 32154

HP - SSRT080133

HP - HPSBST02372

Related Patches

WinZip 11.2 SR-1 (Update) (See Notes) (Rev 2)


Last Updated: 27 May 2016 10:49:54