CVE-2014-3802

msdia.dll in Microsoft Debug Interface Access (DIA) SDK, as distributed in Microsoft Visual Studio before 2013, does not properly validate an unspecified variable before use in calculating a dynamic-call address, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDB file.
References
Link Resource
http://www.securityfocus.com/bid/67398 Third Party Advisory VDB Entry
http://zerodayinitiative.com/advisories/ZDI-14-129/ Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:debug_interface_access_software_development_kit:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:2002:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:2003:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:2005:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:2010:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:2010:sp1:*:*:*:*:*:*

History

No history.

Information

Published : 2014-05-20 23:55

Updated : 2024-02-04 18:35


NVD link : CVE-2014-3802

Mitre link : CVE-2014-3802

CVE.ORG link : CVE-2014-3802


JSON object : View

Products Affected

microsoft

  • visual_studio
  • debug_interface_access_software_development_kit
CWE
CWE-20

Improper Input Validation