42730 : Microsoft Excel BIFF File Format Rich Text Tag Malformed Tag Memory Corruption
Printer | http://osvdb.org/42730 | Email This | Edit Vulnerability

Views This Week

8

Views All Time

832

Info

Last Modified

8 months ago

Percent Complete

100%

Disclosure

Mar 11, 2008

Discovery

Oct 17, 2007

Dates

Exploit

Unknown

Solution

Mar 11, 2008

Description

A buffer overflow exists in Excel. The program fails to validate BIFF files resulting in a heap overflow. With a specially crafted file, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local Access Required, Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch
Exploit: Exploit Unknown
Disclosure: Vendor Verified
OSVDB: Context Dependent

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation
Watch-list
Office
Watch-list
2004 for Mac
2008 for Mac
Excel
Watch-list
2000 SP3
2003 SP2
2002 SP3
Excel Viewer
Watch-list
2003
Office Compatibility Pack for Word, Excel and Powerpoint
Watch-list
2007

References

Tools & Filters

Nessus

31413

Credit

  • Cody Pierce - cpierceBrand New Doo Doocitadel.com - Citadel Security Software

Blogs

Sun Mar 23 22:34:26 -0500 2008 | March 2008 Monthly Release

from: The Security Blog

Wow! It is already the 2nd Tuesday of the month, and with it comes the announcement of some new bulletins! ... and all have a maximum severity rating of Critical. Here is a quick list of what we released: MS08-014

Thu Mar 20 22:47:40 -0500 2008 | Windows Vista SP1 Available

from: Internet/Network Security on About.com

permalink | comments (0) Four Security Bulletins From Microsoft - All Critical For March, Microsoft released only four new Security Bulletins, ... identified in MS08-014. That increases the urgency of applying the MS08-014 patch

Wed Mar 19 19:29:00 -0500 2008 | March 2008 MS08-014 Re-release

from: Bink.nu

March 2008 MS08-014 Re-release Posted by Steven Bink about 5 minutes ago with no comments Filed under: Security wanted to let you know that we've just re-released MS08-014 for Microsoft Office ... through all the same distribution channels as the original MS08-014 security update. It is also

Wed Mar 19 18:49:02 -0500 2008 | Microsoft Fixes MS08-014 Excel Bug

from: PC Magazine Security Watch - Tech Security News, Reviews, Patches and Advice

Microsoft has re-issued one of the updates from last Patch Tuesday.

Mon Mar 17 10:31:13 -0500 2008 | Microsoft Excel patch causes bad maths

from: Intoweb Marketing Online blog covering the latest marketing news - South Africa

Apparently there is a bug in the recently issued MS08-014 Excel security patch issued by Microsoft earlier this week, so if you’ve installed this one you might like to check your worksheets. The bug

Sat Mar 15 02:06:00 -0500 2008 | Update: March 2008 Monthly Release

from: Microsoft News Weblog

Update: March 2008 Monthly Release March 15th, 2008 I wanted to let you know that we have updated bulletin MS08-014 to provide additional information on a newly identified issue that causes

Fri Mar 14 21:08:18 -0500 2008 | Just-patched Excel makes calculation mistakes

from: InfoWorld - Information Technology News, Computer Networking & Security

Microsoft told Excel users Thursday that one of the 12 patches issued Tuesday causes the spreadsheet to make mistakes in some calculations ... that the fixes outlined in the MS08-014 bulletin "causes Microsoft Excel 2003 calculations to return ... to MS08-014, Excel 2003 Service Pack 2 (SP2) and Excel 2003 SP3 return an incorrect result -- usually

Sat Mar 15 05:10:22 -0500 2008 | Microsoft Security Bulletin MS08-014 - Critical Update

from: D' Technology Weblog: Technology, Blogging, Tips, Tricks, Computer, Hardware, Software, Tutorials, Internet, Web, Gadgets, Fashion, LifeStyle, Entertainment, News and more by Deepak Gupta.

Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (949029) ... Gupta's - D' Technology Weblog Microsoft Security Bulletin MS08-014 - Critical Update Tags: Excel

Sat Mar 15 04:44:05 -0500 2008 | MS patch for Excel causes calulation errors

from: Dan’s Tech-n-Stuff Weblog

MS patch for Excel causes calulation errors Posted on March 15, 2008 by Dan [ excel_2003] ... in MS08-014 bulletin “causes Microsoft Excel 2003 calculations to return an incorrect result

Thu Mar 13 14:16:23 -0500 2008 | Websense® - Security Labs Alert: Websense Discovers Microsoft Excel High-risk Zero-day Vulnerability - Patch Released

from: Chris Mosby at myITforum.com

Websense® - Security Labs Alert: Websense Discovers Microsoft Excel High-risk Zero-day Vulnerability - Patch Released March 10, ... in Microsoft Security Bulletin MS08-014. All addressed vulnerabilities in Microsoft Security Bulletin MS08-014: Excel Data Validation Record Vulnerability – CVE-2008-0111 Excel File Import Vulnerability –

Comments

No Comments.

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use