Array index vulnerability in Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP3; Excel Viewer 2003 Gold and SP3; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via an Excel spreadsheet with a NAME record that contains an invalid index value, which triggers stack corruption, aka "Excel Global Array Memory Corruption Vulnerability."
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://secunia.com/secunia_research/2008-36/ | vendor advisory |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-074 | vendor advisory |
http://www.vupen.com/english/advisories/2008/3386 | vdb entry vendor advisory |
http://www.securityfocus.com/archive/1/499055/100/0/threaded | mailing list |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5808 | signature vdb entry |
http://www.securitytracker.com/id?1021368 | vdb entry |
http://www.us-cert.gov/cas/techalerts/TA08-344A.html | third party advisory us government resource |