44214 : Microsoft Windows GDI WMF Handling CreateDIBPatternBrushPt Function Overflow
Printer | http://osvdb.org/44214 | Email This | Edit Vulnerability

Views This Week

68

Views All Time

393

Info

Last Modified

about 1 month ago

Percent Complete

100%

Disclosure

Apr 08, 2008

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Apr 08, 2008

Description

A buffer overflow exists in Windows. GDI fails to validate EMF and WMF image files resulting in a buffer overflow. With a specially crafted file, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local Access Required, Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch
Exploit: Exploit Unknown
Disclosure: Vendor Verified
OSVDB: Context Dependent

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation
Watch-list
Windows
Watch-list
XP SP2
2003 Server SP1
XP Pro x64 Edition SP2
2003 Server SP1 for Itanium
2003 Server SP2
2003 Server x64
2003 Server SP2 x64
2000 SP4
Vista
2003 Server SP2 for Itanium
Vista SP1
Vista x64
Vista SP1 x64 Edition
2008 Server
XP Pro x64 Edition

References

Credit

  • Jun Mao - iDefense Labs
  • Sebastian Apelt - webmasterBrand New Doo Doobuzzworld.org -
  • Thomas Garnier - SkyRecon
  • Yamata Li - Palo Alto Networks

Blogs

2008/04/23 03:14:17 | A quick look at the MS08-021 stack overflows

from: BeOCD

Someone had asked my opinion of these, so I took a quick (like 30 minutes) look at them and at the exploit that was posted on milw0rm. I say these because there were a number of functions changed in the last patch, mostly removing ‘dangerous’ function calls (lstrcpyW, wcsncpy, etc) and replacing them with safer variants

2008/04/17 12:48:39 | Chinese Windows 2000 attack crashes PCs

from: Tech Freaks - Technology n yr Hands - Powered by Students

Security researchers have spotted malicious code that triggers a critical vulnerability in the Chinese version of Windows 2000, ... last week, the company also urged users to deploy the fixes outlined by Microsoft in its MS08-021

2008/04/16 02:48:00 | It's blow up the server day

from: The Official Blog of the SBS "Diva"

SANS Internet Storm Center; Cooperative Network Security Community - Internet Security - isc: http://www.incidents.org/diary.html? ... . That GDI one, MS08-021 KB948590...that sucker already is patched on the workstations last weekend

2008/04/13 07:17:49 | Hackers Attack Newest Windows Patch

from: Barthos Computers Blog

Hackers are trying to exploit a critical Windows vulnerability just patched on Tuesday, security researchers say – and the only version of Windows not at risk is the unfinished Windows XP SP3. Fortunately, attack incompetence means that these initial sorties have been unsuccessful, Symantec Corp

2008/04/14 20:16:10 | The First XP SP3 Security Vulnerability

from: Windows Guides | Mintywhite.com

The third and final service pack for Windows XP is not even out, and Microsoft is already hammering away at it plugging security soles ... Security Bulletin MS08-021 labeled with a maximum severity rating of Critical, Microsoft stated

2008/04/14 19:27:04 | MS08-021 Exploit Activity Increasing

from: Computer Security Research - McAfee Avert Labs Blog

Last week we discussed the fact that Microsoft credited three different researchers for reported CVE-2008-1087 during our monthly Patch Tuesday ... be repeating itself, though out of sequence. Last Friday the first MS08-021 exploit was discovered ... was released prior to this recent exploit activity it is unlikely that MS08-021 attacks will reach

2008/04/13 15:11:21 | Hackers attack latest Windows patch

from: That Damn PC

Hackers are trying to exploit a critical Windows vulnerability recently patched on Tuesday, security researchers say and the only version of Windows not at risk is the unfinished Windows XP SP3. Fortunately, attack incompetence means that these initial sorties have been unsuccessful, Symantec Corp

2008/04/11 06:43:39 | Attacks Begin Against Critical Patch Tuesday Bug

from: Welcome « Salil’s blog

Hackers are trying to exploit a critical Windows vulnerability just patched on Tuesday, security researchers said this afternoon — and the only version of Windows not at risk is the unfinished Windows XP SP3. Fortunately, attack incompetence means that these initial sorties have been unsuccessful,

2008/04/10 21:28:48 | Symantec Raises Threat Level Due To In The Wild Image File Exploits

from: NIST IT Security: News

Symantec has raised the Threatcon to Level 2 due to detection of an in the wild exploit of MS08-021 which allows remote code execution.

2008/04/09 09:01:32 | Patch Tuesday Addresses Client-Side Vulnerabilities

from: Gizmo Spot | Gizmo News, Gadget Reviews and Technology Updates

Patch Tuesday Addresses Client-Side Vulnerabilities April 09th, 2008 | Category: Technology News Another month, another Patch Tuesday ... , Qualys suggests IT departments give three instant attention: MS08-021, MS08-022 and MS08-023

2008/04/09 06:20:09 | Patch Tuesday Addresses Client-Side Vulnerabilities

from: Breaking World News!

Another month, another Patch Tuesday. For April, Microsoft has issued eight security bulletins that address 10 vulnerabilities, ... IT departments give three immediate attention: MS08-021, MS08-022 and MS08-023. These three

Comments

No Comments.

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use