BUGTRAQ ID: 31067
CVE ID:CVE-2008-3007
CNCVE ID:CNCVE-20083007
Microsoft Office OneNote是一款Microsoft Office 系统的一个集成部分,用于帮助管理信息过载,更加轻松地共享信息,并且更加高效地与他人协作的程序。
Microsoft Office处理使用OneNote协议处理器(onenote://)的URL存在缓冲区溢出,远程攻击者可以利用漏洞以应用程序权限执行任意指令。
构建特殊的onenote:// URL可触发此漏洞。目前没有详细漏洞细节提供。
Microsoft OneNote 2007 SP1
Microsoft OneNote 2007 0
Microsoft Office XP SP3
+ Microsoft Excel 2002 SP3
+ Microsoft FrontPage 2002 SP3
+ Microsoft Outlook 2002 SP3
+ Microsoft PowerPoint 2002 SP3
+ Microsoft Publisher 2002 SP3
Microsoft Office XP SP2
- Microsoft Windows 2000 Professional SP3
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 98
- Microsoft Windows 98SE
- Microsoft Windows ME
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home SP1
- Microsoft Windows XP Home
- Microsoft Windows XP Professional SP1
- Microsoft Windows XP Professional
Microsoft Office XP SP1
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 98
- Microsoft Windows ME
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home
- Microsoft Windows XP Professional
Microsoft Office XP
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 98
- Microsoft Windows ME
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows XP Home
- Microsoft Windows XP Professional
Microsoft Office 2007 SP1
Microsoft Office 2007 0
+ Microsoft Access 2007 0
+ Microsoft Excel 2003
+ Microsoft Excel 2007 0
+ Microsoft FrontPage 2003
+ Microsoft Groove 2007 0
+ Microsoft InfoPath 2003
+ Microsoft InfoPath 2007 0
+ Microsoft Office Communicator 2007 0
+ Microsoft OneNote 2003 0
+ Microsoft Outlook 2003 0
+ Microsoft Outlook 2007 0
+ Microsoft PowerPoint 2003 0
+ Microsoft PowerPoint 2007 0
+ Microsoft Project Professional 2007 0
+ Microsoft Project Standard 2007 0
+ Microsoft Publisher 2003
+ Microsoft Publisher 2007 0
+ Microsoft SharePoint Designer 2007 0
+ Microsoft Visio Professional 2007 0
+ Microsoft Visio Standard 2007 0
Microsoft Office 2003 SP3
Microsoft Office 2003 SP2
Microsoft Office 2003 SP1
Microsoft Office 2003 0
+ Microsoft Excel 2003
+ Microsoft FrontPage 2003
+ Microsoft InfoPath 2003
+ Microsoft OneNote 2003 0
+ Microsoft Outlook 2003 0
+ Microsoft PowerPoint 2003 0
+ Microsoft Publisher 2003
可参考如下补丁:
Microsoft Office XP SP3
Microsoft Security Update for Microsoft Office XP (KB953405)
<a href=http://www.microsoft.com/downloads/details.aspx?familyid=ef3de64c-fc17 target=_blank>http://www.microsoft.com/downloads/details.aspx?familyid=ef3de64c-fc17</a> -4500-9da4-a3bba97fda6d
Microsoft OneNote 2007 0
Microsoft Security Update for Microsoft Office OneNote 2007 (KB955047)
<a href=http://www.microsoft.com/downloads/details.aspx?familyid=8ac3576c-7873 target=_blank>http://www.microsoft.com/downloads/details.aspx?familyid=8ac3576c-7873</a> -4ac6-8bbc-033f6a7bb395
Microsoft Office 2003 SP2
Microsoft Security Update for Microsoft Office 2003 (KB953404)
<a href=http://www.microsoft.com/downloads/details.aspx?familyid=e670ad22-d3c1 target=_blank>http://www.microsoft.com/downloads/details.aspx?familyid=e670ad22-d3c1</a> -41f7-ba30-6a67139feaa3
Microsoft Office 2007 0
Microsoft Security Update for Microsoft Office 2007 (KB955047)
2007 Microsoft Office System Service Pack 1
<a href=http://www.microsoft.com/downloads/details.aspx?familyid=fb457536-26c5 target=_blank>http://www.microsoft.com/downloads/details.aspx?familyid=fb457536-26c5</a> -428b-97e4-1fc13718266e
Microsoft Office XP SP1
Microsoft Security Update for Microsoft Office XP (KB953405)
<a href=http://www.microsoft.com/downloads/details.aspx?familyid=ef3de64c-fc17 target=_blank>http://www.microsoft.com/downloads/details.aspx?familyid=ef3de64c-fc17</a> -4500-9da4-a3bba97fda6d
Microsoft Office XP SP2
Microsoft Security Update for Microsoft Office XP (KB953405)
<a href=http://www.microsoft.com/downloads/details.aspx?familyid=ef3de64c-fc17 target=_blank>http://www.microsoft.com/downloads/details.aspx?familyid=ef3de64c-fc17</a> -4500-9da4-a3bba97fda6d
Microsoft Office XP
Microsoft Security Update for Microsoft Office XP (KB953405)
<a href=http://www.microsoft.com/downloads/details.aspx?familyid=ef3de64c-fc17 target=_blank>http://www.microsoft.com/downloads/details.aspx?familyid=ef3de64c-fc17</a> -4500-9da4-a3bba97fda6d
Microsoft Office 2007 SP1
Microsoft Security Update for Microsoft Office 2007 (KB955047)
2007 Microsoft Office System Service Pack 1
<a href=http://www.microsoft.com/downloads/details.aspx?familyid=fb457536-26c5 target=_blank>http://www.microsoft.com/downloads/details.aspx?familyid=fb457536-26c5</a> -428b-97e4-1fc13718266e
Microsoft OneNote 2007 SP1
Microsoft Security Update for Microsoft Office OneNote 2007 (KB955047)
<a href=http://www.microsoft.com/downloads/details.aspx?familyid=8ac3576c-7873 target=_blank>http://www.microsoft.com/downloads/details.aspx?familyid=8ac3576c-7873</a> -4ac6-8bbc-033f6a7bb395
Microsoft Office 2003 SP3
Microsoft Security Update for Microsoft Office 2003 (KB953404)
<a href=http://www.microsoft.com/downloads/details.aspx?familyid=e670ad22-d3c1 target=_blank>http://www.microsoft.com/downloads/details.aspx?familyid=e670ad22-d3c1</a> -41f7-ba30-6a67139feaa3
暂无评论