|
Issues the date: 2008-08-12
Renewal date: 2008-08-13
Is affected the system:
Microsoft PowerPoint Viewer 2003
Description:
--------------------------------------------------------------------------------
BUGTRAQ ID: 30552
CVE(CAN) ID: CVE-2008-0120
Microsoft PowerPoint is in the Microsoft Office suite documents demonstration tool.
PowerPoint Viewer 2003 in process when the CString object which in the PPT demonstration document in inlays has the integer overflow crack, if the user were deceived has opened evil intention PPT document, in inlaid the object possibly caused to assign the very few buffers, but the copy mass data, triggered this overflow, caused to be possible finally a use pile of overflow.
<* origin: Ruben Santamarta (ruben@reversemode.com)
Link: http://secunia.com/advisories/31453/
http://www.microsoft.com/technet/security/bulletin/MS08-051.mspx?pf=true
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=739
http://www.us-cert.gov/cas/techalerts/TA08-225A.html
*>
Suggested:
--------------------------------------------------------------------------------
Temporary solution:
* do not open either the preservation is ever not trusted originates or from receives trusts Microsoft which the origin accident receives the Office document.
Manufacturer patch:
Microsoft
---------
Microsoft had already issued a safe announcement for this reason (MS08-051) as well as the corresponding patch:
MS08-051:Vulnerabilities in Microsoft PowerPoint Could Allow Remote Code Execution (949785)
Link: http://www.microsoft.com/technet/security/bulletin/MS08-051.mspx?pf=true
Patch downloading:
http://www.microsoft.com/downloads/details.aspx?FamilyId=911c8872-dec8-4b8e-9708-93dcabd3e036&displaylang=en
|