Microsoft GDI+ Memory Corruption Error in Processing EMF Image Files Lets Remote Users Execute Arbitrary Code
|
SecurityTracker Alert ID: 1020835 |
SecurityTracker URL: http://securitytracker.com/id/1020835
|
CVE Reference:
CVE-2008-3012
(Links to External Site)
|
Updated: Dec 10 2008
|
Original Entry Date: Sep 9 2008
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 2003 SP2, XP SP3, Vista SP1, 2008; and prior service packs; 2000 SP4 when running IE 6 SP1 or .NET
|
Description:
A vulnerability was reported in Microsoft GDI+ in the processing of EMF image files. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create a specially crafted EMF image file that, when loaded by the target user, will trigger a memory corruption error and execute arbitrary code on the target system. The code will run with the privileges of the target user.
Bing Liu of Fortinet's FortiGuard Global Security Research Team reported this vulnerability.
|
Impact:
A remote user can create an image file that, when loaded by the target user, will execute arbitrary code on the target user's system.
|
Solution:
The vendor has issued the following fixes:
Windows XP Service Pack 2 and Windows XP Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=e0bd6fbe-f46e-4961-9a79-49ec77d39439
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=c5d26771-1f49-4bbf-902c-bf92e527cadb
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=ac03f138-eca4-46e1-9782-e811820e547f
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=93f1451b-5b62-47e5-8f0c-b720b957999a
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=14e99f8a-cdd4-40d7-8cfc-73ae6bd6dfad
Windows Vista and Windows Vista Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=16f3ad21-ed77-4c32-93df-3b650b2b32a5
Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=aa47d016-f5c9-4586-8876-f1f4f255f54d
Windows Server 2008 for 32-bit Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=23bd3be5-cc66-46f8-9420-49d65d8afe1d
Windows Server 2008 for x64-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=7f1e0f05-6c9d-4ad1-9b19-50ee4fa7bd7e
Windows Server 2008 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=5159bdba-3825-4816-a2be-ab035332b9e2
Microsoft Windows 2000 Service Pack 4, Microsoft Internet Explorer 6 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=a860d2d9-653d-4ddb-bbff-323d3ccdb866
Microsoft Windows 2000 Service Pack 4, Microsoft .NET Framework 1.0 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=C7CBCD19-ACC1-4A89-ADFA-99B2F431510D
Microsoft .NET Framework 1.1 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?FamilyId=6013F866-3EA1-4672-B1BF-E516204C3A7A
Microsoft .NET Framework 2.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=7F1CD013-2C4B-4582-9114-CB840A96124A
Microsoft .NET Framework 2.0 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?FamilyId=215B73A3-46AB-44A8-A0FB-6D37BD1C39B8
Microsoft Office XP Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=ef3de64c-fc17-4500-9da4-a3bba97fda6d
Microsoft Office 2003 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=e9f8e309-d721-4bab-b485-5eede8d49eb8
Microsoft Office 2003 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=e9f8e309-d721-4bab-b485-5eede8d49eb8
2007 Microsoft Office System:
http://www.microsoft.com/downloads/details.aspx?familyid=4b656fe8-6253-490c-a81a-e4e8f0bb58d2
2007 Microsoft Office System Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=4b656fe8-6253-490c-a81a-e4e8f0bb58d2
Microsoft Office Project 2002 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=ef3de64c-fc17-4500-9da4-a3bba97fda6d
Microsoft Visio 2002 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=a6d9d3ef-f087-4f61-9ec1-522b7d4b9c48
Microsoft Office Word Viewer, Microsoft Word Viewer 2003, Microsoft Word Viewer 2003 Service Pack 3, Microsoft Office Excel Viewer 2003, Microsoft Office Excel Viewer 2003 Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=e9f8e309-d721-4bab-b485-5eede8d49eb8
Microsoft Office PowerPoint Viewer 2003:
http://www.microsoft.com/downloads/details.aspx?familyid=cd503f08-1831-45ff-bdf4-dd918ca40505
Microsoft Office Excel Viewer, Microsoft Office PowerPoint Viewer 2007, Microsoft Office PowerPoint Viewer 2007 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=4b656fe8-6253-490c-a81a-e4e8f0bb58d2
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=4b656fe8-6253-490c-a81a-e4e8f0bb58d2
Microsoft Expression Web and Microsoft Expression Web 2:
http://www.microsoft.com/downloads/details.aspx?familyid=4b656fe8-6253-490c-a81a-e4e8f0bb58d2
Microsoft Office Groove 2007 and Microsoft Office Groove 2007 Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=4b656fe8-6253-490c-a81a-e4e8f0bb58d2
Microsoft Works 8:
http://www.microsoft.com/downloads/details.aspx?familyid=EB0D224E-A517-40D9-9FC6-2345FA12A841
Microsoft Digital Image Suite 2006:
http://www.microsoft.com/downloads/details.aspx?familyid=04afd760-8173-4069-9e82-d3bf053d9eae
See the advisory for additional product solution URLs.
The vendor's advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms08-052.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms08-052.mspx (Links to External Site)
|
Cause:
Access control error
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|