CVE-2007-6026

Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.
References
Link Resource
http://dvlabs.tippingpoint.com/advisory/TPTI-08-04
http://lists.grok.org.uk/pipermail/full-disclosure/2007-November/058531.html
http://marc.info/?l=bugtraq&m=121129490723574&w=2
http://marc.info/?l=bugtraq&m=121129490723574&w=2
http://ruder.cdut.net/blogview.asp?logID=227
http://securityreason.com/securityalert/3376
http://www.kb.cert.org/vuls/id/936529 US Government Resource
http://www.securityfocus.com/archive/1/483797/100/0/threaded
http://www.securityfocus.com/archive/1/483858/100/100/threaded
http://www.securityfocus.com/archive/1/483887/100/100/threaded
http://www.securityfocus.com/archive/1/483888/100/100/threaded
http://www.securityfocus.com/archive/1/492019/100/0/threaded
http://www.securityfocus.com/bid/26468
http://www.securityfocus.com/bid/28398
http://www.securitytracker.com/id?1018976
http://www.us-cert.gov/cas/techalerts/TA08-134A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-028
https://exchange.xforce.ibmcloud.com/vulnerabilities/38499
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5578
http://dvlabs.tippingpoint.com/advisory/TPTI-08-04
http://lists.grok.org.uk/pipermail/full-disclosure/2007-November/058531.html
http://marc.info/?l=bugtraq&m=121129490723574&w=2
http://marc.info/?l=bugtraq&m=121129490723574&w=2
http://ruder.cdut.net/blogview.asp?logID=227
http://securityreason.com/securityalert/3376
http://www.kb.cert.org/vuls/id/936529 US Government Resource
http://www.securityfocus.com/archive/1/483797/100/0/threaded
http://www.securityfocus.com/archive/1/483858/100/100/threaded
http://www.securityfocus.com/archive/1/483887/100/100/threaded
http://www.securityfocus.com/archive/1/483888/100/100/threaded
http://www.securityfocus.com/archive/1/492019/100/0/threaded
http://www.securityfocus.com/bid/26468
http://www.securityfocus.com/bid/28398
http://www.securitytracker.com/id?1018976
http://www.us-cert.gov/cas/techalerts/TA08-134A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-028
https://exchange.xforce.ibmcloud.com/vulnerabilities/38499
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5578
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:jet:4.0.8618.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*

History

21 Nov 2024, 00:39

Type Values Removed Values Added
References () http://dvlabs.tippingpoint.com/advisory/TPTI-08-04 - () http://dvlabs.tippingpoint.com/advisory/TPTI-08-04 -
References () http://lists.grok.org.uk/pipermail/full-disclosure/2007-November/058531.html - () http://lists.grok.org.uk/pipermail/full-disclosure/2007-November/058531.html -
References () http://marc.info/?l=bugtraq&m=121129490723574&w=2 - () http://marc.info/?l=bugtraq&m=121129490723574&w=2 -
References () http://ruder.cdut.net/blogview.asp?logID=227 - () http://ruder.cdut.net/blogview.asp?logID=227 -
References () http://securityreason.com/securityalert/3376 - () http://securityreason.com/securityalert/3376 -
References () http://www.kb.cert.org/vuls/id/936529 - US Government Resource () http://www.kb.cert.org/vuls/id/936529 - US Government Resource
References () http://www.securityfocus.com/archive/1/483797/100/0/threaded - () http://www.securityfocus.com/archive/1/483797/100/0/threaded -
References () http://www.securityfocus.com/archive/1/483858/100/100/threaded - () http://www.securityfocus.com/archive/1/483858/100/100/threaded -
References () http://www.securityfocus.com/archive/1/483887/100/100/threaded - () http://www.securityfocus.com/archive/1/483887/100/100/threaded -
References () http://www.securityfocus.com/archive/1/483888/100/100/threaded - () http://www.securityfocus.com/archive/1/483888/100/100/threaded -
References () http://www.securityfocus.com/archive/1/492019/100/0/threaded - () http://www.securityfocus.com/archive/1/492019/100/0/threaded -
References () http://www.securityfocus.com/bid/26468 - () http://www.securityfocus.com/bid/26468 -
References () http://www.securityfocus.com/bid/28398 - () http://www.securityfocus.com/bid/28398 -
References () http://www.securitytracker.com/id?1018976 - () http://www.securitytracker.com/id?1018976 -
References () http://www.us-cert.gov/cas/techalerts/TA08-134A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA08-134A.html - US Government Resource
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-028 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-028 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/38499 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/38499 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5578 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5578 -

Information

Published : 2007-11-20 00:46

Updated : 2024-11-21 00:39


NVD link : CVE-2007-6026

Mitre link : CVE-2007-6026

CVE.ORG link : CVE-2007-6026


JSON object : View

Products Affected

microsoft

  • windows_2003_server
  • office
  • windows_nt
  • windows_2000
  • windows_xp
  • jet
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer