44213 : Microsoft Windows GDI (gdi32.dll) EMF File Handling Multiple Overflows
Printer | http://osvdb.org/44213 | Email This | Edit Vulnerability

Views This Week Views All Time Added to OSVDB Last Modified Modified (since 2008) Percent Complete
9 1603 about 1 year ago 2 months ago 15 times 100%

Timeline

Vendor Informed Date Vendor Ack Date Disclosure Date Vendor Solution Date Discovery Date
2007-12-17 2007-12-17 2008-04-08 2008-04-08 2008-12-17
Time to Patch
113 days

Keywords

c01433452, HPSBST02329, SSRT080048 c01433452, HPSBST02329, SSRT080048

Description

A heap overflow overflow exists in Windows. gdi32.dll fails to validate EMF files resulting in a heap overflow. With a specially crafted file, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local Access Required, Remote / Network Access, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public, Exploit Private
Disclosure: Vendor Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation
Watch-list
Windows
Watch-list
XP SP2
XP Pro x64
2003 Server x64
2000 SP4
Vista
2003 Server for Itanium
2003 Server SP1
Vista SP1
2008 Server
Vista x64 SP1
2003 Server x64 SP2
2003 Server for Itanium SP2
XP Pro x64 SP2
Vista x64

References

Credit

CVSSv2 Score

CVSSv2 Base Score = 9.3
Source: nvd.nist.gov | Generated: 2008-04-09 | Disagree?

Access_vector_2 Access_complexity_1 Authentication_2 Confidentiality_impact_2 Integrity_impact_2 Availability_impact_2

Blogs

This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.

2008/04/09 13:20:09 | Patch Tuesday Addresses Client-Side Vulnerabilities

from: NewsFactor Network

Another month, another Patch Tuesday. For April, Microsoft has issued eight security bulletins that address 10 vulnerabilities, ... IT departments give three immediate attention: MS08-021, MS08-022 and MS08-023. These three

2008/05/10 04:49:18 | Sourcefire® Delivers Same Day Protection for Microsoft Tuesday Vulnerabilities

from: voip equipment

Sourcefire Vulnerability Research Team Protects Users from Latest Microsoft Windows Vulnerabilities Open source innovator and SNORT® creator, ... Enhancement Update (SEU) released today. Microsoft Security Bulletin MS08-021 – Critical

2008/05/07 16:43:26 | Critical Vulnerability Targets Windows Metafiles

from: IT, computer and network security Portal

Critical Vulnerability Targets Windows Metafiles SkyRecon Systems has announced that StormShield blocks against a known vulnerability CVE-2008-1083 recently identified by the research engineers

2008/04/22 10:13:58 | Microsoft latest patches

from: Application - Network - Wireless Security

Microsoft Issues eight security patches for April 2008 MS08-018: Vulnerability in Microsoft Project Could Allow Remote Code Execution MS08-019: Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution MS08-020: Vulnerability in DNS Client Could Allow Spoofing MS08-021: Vulnerabilities in GDI Could Allow Remote Code Execution

2008/04/17 14:43:00 | On exploiting MS08-021 (CVE-2008-1083)

from: BeOCD

So I managed to create a simple proof of concept for the vulnerability, thanks to the 010 Editor (which is just plain hawt) and a WMF template. Anyhow, here is what it looks like: We obviously need cjBitmapBitSize to return a value large enough to trigger the arithmetic overflow, which means we need something around 0xFFFFFF00

2008/04/14 17:31:00 | A look at MS08-021 (CVE-2008-1083) (again…)

from: BeOCD

Those of you that are observant will notice that I removed the previous two posts regarding this vulnerability in favor of completely rewriting the ... . The one I chose to detail is CVE-2008-1083 which is an integer overflow when handling WMF files

2008/04/16 21:57:24 | Attackers exploit recent Microsoft fix

from: Techachino

Hackers continue trying to exploit a patched vulnerability in Microsoft’s Graphic Display Interface (GDI), researchers said this week ... on Friday, three days after the issue was patched by bulletin MS08-021. “One method the bad guys use ... the updates detailed in MS08-021, said Bill Sisk, security response communications manager for Microsoft

2008/04/15 17:13:46 | MS08-021: A Must-Patch Vulnerability

from: Messaging & Collaboration

Virus hunters are tracking a booby-trapped file named TOP.JPG in circulation and exploiting one of the vulnerabilities described in Microsoft's MS08-001 bulletin. ... Check Out The #1 Technology Research Tool! SEARCH The Most Massive Development White Paper Library In The Industry.

2008/04/15 14:09:12 | The First XP SP3 Security Vulnerability

from: Tech Freaks - Technology n yr Hands - Powered by Students

The third and final service pack for Windows XP is not even out, and Microsoft is already hammering away at it plugging security soles ... . When it released Microsoft Security Bulletin MS08-021 labeled with a maximum severity rating of Critical

2008/04/14 16:05:18 | Microsoft patched critical Windows bug in XP SP3 early

from: InfoWorld - Information Technology News, Computer Networking & Security

The appearance and disappearance of a Windows XP installation snafu indicates that Microsoft patched a critical vulnerability in XP's still-unfinished Service Pack 3 (SP3) weeks before it fixed any other version of Windows. The glitch, which sent some PCs into an endless round of reboots,

2008/04/13 11:35:00 | Code Reuse Causes Problems

from: Sûnnet Beskerming - Make the Most of What You've Got

As alluded to in the pre-advisory for Microsoft's April Security Patch Release, ... cycles. The biggest indication of this can be seen with the GDI library patch, MS08-021, which ... are vulnerable to the two critical vulnerabilities patched by MS08-021, including one WMF image handling

2008/04/11 20:56:00 | Microsoft April Security Updates - MS08-021 Exploit in-the-wild

from: Harry Waldron - My IT Forums Blog

Based on ISC and Symantec's warnings below, it appears that MS08-021 is being actively exploited in the wild It is advised that folks apply the ... Updates - MS08-021 Exploit in-the-wild http://isc.sans.org/diary.html?storyid=4274 www.symantec.com ... are advised to apply the MS08-021 patches immediately. These attack attempts highlight the severity

2008/04/11 20:53:00 | Microsoft April Security Updates - MS08-021 Exploit in-the-wild

from: Blogs - MSMVPS.COM

Based on ISC and Symantec's warnings below, it appears that MS08-021 is being actively exploited in the wild It is advised that folks apply the ... Updates - MS08-021 Exploit in-the-wild http://isc.sans.org/diary.html?storyid=4274 www.symantec.com ... are advised to apply the MS08-021 patches immediately. These attack attempts highlight the severity

2008/04/09 22:41:00 | Microsoft Patches Critical Bugs in Windows Graphics System

from: Information Engineer - Technology News

Microsoft issued a critical patch for two vulnerabilities in the core graphics subsystem of Windows, ... in the industry as “Patch Tuesday.” MS08-021 fixes two vulnerabilities in Windows’ graphics device interface (GDI

2008/04/09 21:08:22 | Microsoft Issues Critical Fixes to Windows, Apps

from: Learning Remix Winter 2008

Following the release of Windows Vista Service Pack 1 and Windows Server 2008, Microsoft is serving up a number of fixes for both operating systems, ... McAfee, is MS08-021, which fixes two vulnerabilities in Windows that would allow an attacker

2008/04/09 14:42:52 | Microsoft Patches Critical Bugs in Windows Graphics System

from: BAK2u.com - Anti-theft softwares for PDA phones, Blackberry, Mobile Phones, iPods, PSPs, USB Flash Drive, Laptops

Microsoft issued a critical patch for two vulnerabilities in the core graphics subsystem of Windows, ... as "Patch Tuesday." MS08-021 fixes two vulnerabilities in Windows' graphics device interface (GDI

2008/04/08 16:47:00 | April 2008 Monthly Release

from: The Microsoft Security Response Center (MSRC)

April 2008 Monthly Bulletin Release I'm Simon, Release Manager in the MSRC ... ) MS08-020 Vulnerability in DNS Client Could Allow Spoofing (945553) MS08-021

2008/04/09 02:34:04 | New Vista Patches

from: Fix Windows Vista Errors

In the first month following the release of Windows Vista Service Pack 1 and Windows Server 2008, ... , the critical vulnerability involving GDI — MS08-021 — will affect Windows 2000 SP4, Windows XP SP2, Windows XP

2008/04/09 01:56:20 | Microsoft patches critical bugs in Windows graphics system

from: InfoWorld - Information Technology News, Computer Networking & Security

Microsoft issued a critical patch for two vulnerabilities in the core graphics subsystem of Windows, ... as "Patch Tuesday." MS08-021 fixes two vulnerabilities in Windows' GDI (graphics device interface

2008/04/09 01:10:15 | Patches for Critical Bugs in Windows ActiveX System Released

from: Tech-Blog by Jithesh

Patches for Critical Bugs in Windows ActiveX System Released Posted by Jithesh at April 8, 2008 [ Microsoft] ... in the industry as “Patch Tuesday.” * MS08-018, fixes for vulnerabilities in Microsoft Office * MS08-021 fixes ... . In Sarwate’s opinion, MS08-021, MS08-022 and MS08-023 are especially important for users because

2008/04/08 21:28:59 | Microsoft patches critical top-to-bottom bugs in Windows

from: WinBeta.org Beta News and Reviews

Microsoft Corp. today posted eight security updates -- more than half marked "critical" -- that patch 10 bugs in Windows, ... vulnerabilities disclosed today were the two plugged by MS08-021, a critical update for every currently

2008/04/08 19:01:03 | Busy Day - Kraken, New Storm Run, and MSFT Bulletins

from: Security to the Core | Arbor Networks Security

Kraken, the spam botnet on everyone’s minds, has soaked up a good bit of out Monday evening and today ... . Go get patched! The ones that have me worried about widespread exploitation: MS08-021

Comments

No Comments.

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2010 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use