Vulnerabilities > CVE-2008-0120 - Resource Management Errors vulnerability in Microsoft Office Powerpoint Viewer 2003
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka "Memory Allocation Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS08-051.NASL |
description | The remote host is running a version of Microsoft PowerPoint which is subject to a flaw that could allow arbitrary code to be run. An attacker may use this to execute arbitrary code on this host. To succeed, the attacker would have to send a rogue file to a user of the remote computer and have it open it. Then a bug in the font parsing handler would result in code execution. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 33880 |
published | 2008-08-13 |
reporter | This script is Copyright (C) 2008-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/33880 |
title | MS08-051: Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (949785) |
code |
|
Oval
accepted | 2014-06-30T04:11:05.664-04:00 | ||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||
contributors |
| ||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||
description | Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka "Memory Allocation Vulnerability." | ||||||||||||||||||||
family | windows | ||||||||||||||||||||
id | oval:org.mitre.oval:def:5768 | ||||||||||||||||||||
status | accepted | ||||||||||||||||||||
submitted | 2008-08-13T09:28:00 | ||||||||||||||||||||
title | Memory Allocation Vulnerability | ||||||||||||||||||||
version | 13 |
Saint
bid | 30552 |
description | Microsoft PowerPoint Viewer picture index CString object integer overflow |
id | win_patch_pptview2003 |
osvdb | 47406 |
title | powerpoint_viewer_cstring |
type | client |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 30552 CVE(CAN) ID: CVE-2008-0120 Microsoft PowerPoint是微软Office套件中的文档演示工具。 PowerPoint Viewer 2003在处理PPT演示文件中内嵌的CString对象时存在整数溢出漏洞,如果用户受骗打开了恶意的PPT文件的话,内嵌的对象可能导致分配很少的缓冲区而拷贝大量数据,触发这个溢出,最终导致可利用的堆溢出。 Microsoft PowerPoint Viewer 2003 临时解决方法: * 不要打开或保存从不受信任来源或从受信任来源意外收到的Microsoft Office文件。 厂商补丁: Microsoft --------- Microsoft已经为此发布了一个安全公告(MS08-051)以及相应补丁: MS08-051:Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (949785) 链接:<a href=http://www.microsoft.com/technet/security/bulletin/MS08-051.mspx?pf=true target=_blank>http://www.microsoft.com/technet/security/bulletin/MS08-051.mspx?pf=true</a> 补丁下载: <a href=http://www.microsoft.com/downloads/details.aspx?FamilyId=911c8872-dec8-4b8e-9708-93dcabd3e036&displaylang=en target=_blank>http://www.microsoft.com/downloads/details.aspx?FamilyId=911c8872-dec8-4b8e-9708-93dcabd3e036&displaylang=en</a> |
id | SSV:3829 |
last seen | 2017-11-19 |
modified | 2008-08-14 |
published | 2008-08-14 |
reporter | Root |
title | Microsoft PowerPoint Viewer 2003 Cstring对象整数溢出漏洞(MS08-051) |
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=739
- http://marc.info/?l=bugtraq&m=121915960406986&w=2
- http://secunia.com/advisories/31453
- http://www.securityfocus.com/bid/30552
- http://www.securitytracker.com/id?1020676
- http://www.us-cert.gov/cas/techalerts/TA08-225A.html
- http://www.vupen.com/english/advisories/2008/2355
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-051
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5768