CVE-2008-4028
Summary
| CVE | CVE-2008-4028 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-12-10 14:00:00 UTC |
| Updated | 2018-10-30 16:25:00 UTC |
| Description | Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via crafted control words related to multiple Drawing Object tags in (1) an RTF file or (2) a rich text e-mail message, which triggers incorrect memory allocation and a heap-based buffer overflow, aka "Word RTF Object Parsing Vulnerability," a different vulnerability than CVE-2008-4030. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Office | 2000 | sp3 | All | All |
| Application | Microsoft | Office | 2003 | sp3 | All | All |
| Application | Microsoft | Office | xp | sp3 | All | All |
| Application | Microsoft | Office | 2000 | sp3 | All | All |
| Application | Microsoft | Office | 2003 | sp3 | All | All |
| Application | Microsoft | Office | xp | sp3 | All | All |
| Application | Microsoft | Office | 2004 | All | mac | All |
| Application | Microsoft | Office | 2008 | All | mac | All |
| Application | Microsoft | Office | 2004 | All | mac | All |
| Application | Microsoft | Office | 2008 | All | mac | All |
| Application | Microsoft | Office Compatibility Pack For Word Excel Ppt 2007 | All | All | All | All |
| Application | Microsoft | Office Compatibility Pack For Word Excel Ppt 2007 | All | sp1 | All | All |
| Application | Microsoft | Office Compatibility Pack For Word Excel Ppt 2007 | All | All | All | All |
| Application | Microsoft | Office Compatibility Pack For Word Excel Ppt 2007 | All | sp1 | All | All |
| Application | Microsoft | Office Outlook | 2007 | All | All | All |
| Application | Microsoft | Office Outlook | 2007 | sp1 | All | All |
| Application | Microsoft | Office Outlook | 2007 | All | All | All |
| Application | Microsoft | Office Outlook | 2007 | sp1 | All | All |
| Operating System | Microsoft | Office System | All | 2007 | All | All |
| Operating System | Microsoft | Office System | sp1 | 2007 | All | All |
| Operating System | Microsoft | Office System | All | 2007 | All | All |
| Operating System | Microsoft | Office System | sp1 | 2007 | All | All |
| Application | Microsoft | Office Word | 2000 | sp3 | All | All |
| Application | Microsoft | Office Word | 2002 | sp3 | All | All |
| Application | Microsoft | Office Word | 2003 | sp3 | All | All |
| Application | Microsoft | Office Word | 2007 | All | All | All |
| Application | Microsoft | Office Word | 2000 | sp3 | All | All |
| Application | Microsoft | Office Word | 2002 | sp3 | All | All |
| Application | Microsoft | Office Word | 2003 | sp3 | All | All |
| Application | Microsoft | Office Word | 2007 | All | All | All |
| Application | Microsoft | Office Word Viewer | 2003 | All | All | All |
| Application | Microsoft | Office Word Viewer | 2003 | sp3 | All | All |
| Application | Microsoft | Office Word Viewer | 2003 | All | All | All |
| Application | Microsoft | Office Word Viewer | 2003 | sp3 | All | All |
| Application | Microsoft | Open Xml File Format Converter | All | All | mac | All |
| Application | Microsoft | Open Xml File Format Converter | All | All | mac | All |
| Application | Microsoft | Works | 8.0 | All | All | All |
| Application | Microsoft | Works | 8.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zero Day Initiative | MISC | www.zerodayinitiative.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Microsoft Security Bulletin MS08-072 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| Microsoft Word Memory Corruption Errors Let Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Zero Day Initiative | MISC | www.zerodayinitiative.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| US-CERT Technical Cyber Security Alert TA08-344A -- Microsoft Updates for Multiple Vulnerabilities | CERT | www.us-cert.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.