CVE-2007-6026 Information

Description

Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine) as used by Access 2003 in Microsoft Office 2003 SP3 allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.

Reference

http://dvlabs.tippingpoint.com/advisory/TPTI-08-04 http://lists.grok.org.uk/pipermail/full-disclosure/2007-November/058531.html http://marc.info/?l=bugtraq&m=121129490723574&w=2 http://ruder.cdut.net/blogview.asp?logID=227 http://securityreason.com/securityalert/3376 http://www.kb.cert.org/vuls/id/936529 http://www.securityfocus.com/archive/1/483797/100/0/threaded http://www.securityfocus.com/archive/1/483858/100/100/threaded http://www.securityfocus.com/archive/1/483887/100/100/threaded http://www.securityfocus.com/archive/1/483888/100/100/threaded http://www.securityfocus.com/archive/1/492019/100/0/threaded http://www.securityfocus.com/bid/26468 http://www.securityfocus.com/bid/28398 http://www.securitytracker.com/id?1018976 http://www.us-cert.gov/cas/techalerts/TA08-134A.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-028 https://exchange.xforce.ibmcloud.com/vulnerabilities/38499 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A5578

Share on: