[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96174

 
 

909

 
 

78077

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2011-0979

Date: (C)2011-02-10   (M)2017-09-22
 
CVSS Score: 9.3Access Vector: NETWORK
Exploitability Subscore: 8.6Access Complexity: MEDIUM
Impact Subscore: 10.0Authentication: NONE
 Confidentiality: COMPLETE
 Integrity: COMPLETE
 Availability: COMPLETE











Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; and Excel Viewer SP2 do not properly handle errors during the parsing of Office Art records in Excel spreadsheets, which allows remote attackers to execute arbitrary code via a malformed object record, related to a "stray reference," aka "Excel Linked List Corruption Vulnerability."

Reference:
SECTRACK-1025337
SECUNIA-39122
SECUNIA-43231
OSVDB-70904
ADV-2011-0940
MS11-021
TA11-102A
http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-microsoft
http://zerodayinitiative.com/advisories/ZDI-11-041/

CPE    11
cpe:/a:microsoft:office_compatibility_pack:2007:sp2
cpe:/a:microsoft:excel:-:-:x64
cpe:/a:microsoft:excel:2007:sp2
cpe:/a:microsoft:excel:2010
...
CWE    1
CWE-20
OVAL    2
oval:org.secpod.oval:def:211
oval:org.secpod.oval:def:822

© 2013 SecPod Technologies