CVE-2008-1083 Information
Description
Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4 XP SP2 Server 2003 SP1 and SP2 Vista and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow aka \GDI Heap Overflow Vulnerability.\
Reference
http://archives.neohapsis.com/archives/fulldisclosure/2008-04/0168.html http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=681 http://marc.info/?l=bugtraq&m=120845064910729&w=2 http://secunia.com/advisories/29704 http://support.microsoft.com/kb/948590 http://www.kb.cert.org/vuls/id/632963 http://www.osvdb.org/44213 http://www.osvdb.org/44214 http://www.securityfocus.com/archive/1/490584/100/0/threaded http://www.securityfocus.com/bid/28571 http://www.securityfocus.com/bid/30933 http://www.securitytracker.com/id?1019798 http://www.us-cert.gov/cas/techalerts/TA08-099A.html http://www.vupen.com/english/advisories/2008/1145/references http://www.zerodayinitiative.com/advisories/ZDI-08-020/ https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-021 https://exchange.xforce.ibmcloud.com/vulnerabilities/41471 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A5441 https://www.exploit-db.com/exploits/5442 https://www.exploit-db.com/exploits/6330
Share on: