Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: Microsoft Jet Engine MDB File Parsing Stack Overflow Vulnerability

Re: Microsoft Jet Engine MDB File Parsing Stack Overflow Vulnerability

From: Juha-Matti Laurio <juha-matti.laurio_at_netti.fi>
Date: Sun, 18 Nov 2007 01:58:02 +0200 (EET)

There is a well-known unpatched code execution type vulnerability reported originally in msjet40.dll version 4.00.8618.0 too.
This issue reported by HexView is known since March 2005:

http://www.securityfocus.com/bid/12960
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0944

We probably don't see a fix for this issue.

- Juha-Matti

"CaseArmour.net Security Administrator" <security_at_casearmour.net> kirjoitti:
> It would be useful to know if this is also an issue with msjet40.dll
> 4.0.9510.0 (Windows Server 2003 SP2 + hotfixes). I have an installer
> for Windows XP SP2 that -- seems -- to cleanly apply Windows Server 2003
> SP2's MDAC 2.82. I haven't been able to give it a serious, hard testing
> because I don't have many apps that still use MDAC.
>
> On Fri, 16 Nov 2007 19:25:29 +0800, "cocoruder" <cocoruder_at_gmail.com>
> said:
> >
> > (C:\Windows\System32\msjet40.dll, version is 4.0.8618.0)
Received on Nov 19 2007

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]