9.3

CVE-2008-4019

Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office SharePoint Server 2007 Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file containing a formula within a cell, aka "Formula Parsing Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Excel Version 2003 Update sp2
Microsoft ≫ Excel Version 2003 Update sp3
Microsoft ≫ Excel Version 2007 Update -
Microsoft ≫ Excel Version 2007 Update sp1
Microsoft ≫ Excel Viewer Version -
Microsoft ≫ Excel Viewer Version 2003 Update -
Microsoft ≫ Excel Viewer Version 2003 Update sp3
Microsoft ≫ Office Version 2004 SwPlatform macos
Microsoft ≫ Office Version 2008 SwPlatform macos
Microsoft ≫ Office Compatibility Pack Version 2007 Update -
Microsoft ≫ Office Compatibility Pack Version 2007 Update sp1
Microsoft ≫ Open Xml File Format Converter Version - SwPlatform macos
Microsoft ≫ Sharepoint Server Version 2007 HwPlatform x64
Microsoft ≫ Sharepoint Server Version 2007 Update -
Microsoft ≫ Sharepoint Server Version 2007 Update sp1
Microsoft ≫ Sharepoint Server Version 2007 Update sp1 HwPlatform x64
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 34.42% 0.982
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

http://marc.info/?l=bugtraq&m=122479227205998&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://www.us-cert.gov/cas/techalerts/TA08-288A.html
Third Party Advisory
US Government Resource
http://secunia.com/advisories/32211
Patch
Vendor Advisory
http://www.securitytracker.com/id?1021044
Third Party Advisory
VDB Entry
http://www.vupen.com/english/advisories/2008/2808
Third Party Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-057
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/45581
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/31706
Patch
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/45580
Third Party Advisory
VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6102
Third Party Advisory