CVE-2009-0558
Summary
| CVE | CVE-2009-0558 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-06-10 18:30:00 UTC |
| Updated | 2018-10-12 21:50:00 UTC |
| Description | Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing Memory Corruption Vulnerability." |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Office | 2004 | All | mac | All |
| Application | Microsoft | Office | 2008 | All | mac | All |
| Application | Microsoft | Office | xp | sp3 | All | All |
| Application | Microsoft | Office | 2004 | All | mac | All |
| Application | Microsoft | Office | 2008 | All | mac | All |
| Application | Microsoft | Office | xp | sp3 | All | All |
| Application | Microsoft | Office Compatibility Pack For Word Excel Ppt 2007 | All | sp1 | All | All |
| Application | Microsoft | Office Compatibility Pack For Word Excel Ppt 2007 | All | sp2 | All | All |
| Application | Microsoft | Office Compatibility Pack For Word Excel Ppt 2007 | All | sp1 | All | All |
| Application | Microsoft | Office Compatibility Pack For Word Excel Ppt 2007 | All | sp2 | All | All |
| Application | Microsoft | Office Excel | 2000 | sp3 | All | All |
| Application | Microsoft | Office Excel | 2003 | sp3 | All | All |
| Application | Microsoft | Office Excel | 2007 | sp1 | All | All |
| Application | Microsoft | Office Excel | 2007 | sp2 | All | All |
| Application | Microsoft | Office Excel | 2000 | sp3 | All | All |
| Application | Microsoft | Office Excel | 2003 | sp3 | All | All |
| Application | Microsoft | Office Excel | 2007 | sp1 | All | All |
| Application | Microsoft | Office Excel | 2007 | sp2 | All | All |
| Application | Microsoft | Office Excel Viewer | All | All | All | All |
| Application | Microsoft | Office Excel Viewer | 2003 | sp3 | All | All |
| Application | Microsoft | Office Excel Viewer | All | All | All | All |
| Application | Microsoft | Office Excel Viewer | 2003 | sp3 | All | All |
| Application | Microsoft | Office Sharepoint Server | 2007 | sp1 | x32 | All |
| Application | Microsoft | Office Sharepoint Server | 2007 | sp1 | x64 | All |
| Application | Microsoft | Office Sharepoint Server | 2007 | sp2 | x32 | All |
| Application | Microsoft | Office Sharepoint Server | 2007 | sp2 | x64 | All |
| Application | Microsoft | Office Sharepoint Server | 2007 | sp1 | x32 | All |
| Application | Microsoft | Office Sharepoint Server | 2007 | sp1 | x64 | All |
| Application | Microsoft | Office Sharepoint Server | 2007 | sp2 | x32 | All |
| Application | Microsoft | Office Sharepoint Server | 2007 | sp2 | x64 | All |
| Application | Microsoft | Open Xml File Format Converter | All | All | mac | All |
| Application | Microsoft | Open Xml File Format Converter | All | All | mac | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 54954 | OSVDB | osvdb.org | |
| US-CERT Technical Cyber Security Alert TA09-160A -- Microsoft Updates for Multiple Vulnerabilities | CERT | www.us-cert.gov | US Government Resource |
| Microsoft Excel Array Indexing Remote Code Execution Vulnerability | BID | www.securityfocus.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Microsoft Security Bulletin MS09-021 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Vulnerabilities - Secunia Research - Vulnerability Information - Secunia.com | MISC | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - Microsoft Excel Bugs Let Remote Users Execute Arbitrary Code | SECTRACK | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.