Microsoft Jet Database Engine Malformed Database File Buffer Overflow Vulnerability
BID:12960
Info
Microsoft Jet Database Engine Malformed Database File Buffer Overflow Vulnerability
| Bugtraq ID: | 12960 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-0944 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 31 2005 12:00AM |
| Updated: | May 29 2008 03:13PM |
| Credit: | <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Microsoft JET 4.0 SP7 Microsoft JET 4.0 SP6 Microsoft JET 4.0 SP5 Microsoft JET 4.0 SP4 Microsoft JET 4.0 SP3 Microsoft JET 4.0 SP2 Microsoft JET 4.0 SP1 Microsoft JET 4.0 Microsoft JET 3.51 SP3 Microsoft JET 3.51 Microsoft JET 3.5 Microsoft JET 3.0 Microsoft JET 2.5 Microsoft JET 2.0 Microsoft Access 2003 Microsoft Access 2002 SP2 Microsoft Access 2002 SP1 Microsoft Access 2002 Microsoft Access 2000 SR1 Microsoft Access 2000 SP3 Microsoft Access 2000 SP2 Microsoft Access 2000 |
| Not Vulnerable: | |
Discussion
Microsoft Jet Database Engine Malformed Database File Buffer Overflow Vulnerability
Microsoft Jet Database Engine is vulnerable to a buffer-overflow vulnerability because the library fails to properly bounds-check the contents of user-supplied database files.
Attackers may exploit this vulnerability to execute arbitrary machine code in the context of the victim trying to access a malicious Jet database file.
This vulnerability is reported to reside in the 'msjet40.dll' library, version 4.00.8618.0. Older versions may also be affected. The 'msjetole40.dll' OLE (Object Linking and Embedding) library is reportedly immune to this vulnerability.
The Backdoor.Hesive trojan is reported to employ this vulnerability to install itself on vulnerable computers. Please see the web reference for more information.
Microsoft Jet Database Engine is vulnerable to a buffer-overflow vulnerability because the library fails to properly bounds-check the contents of user-supplied database files.
Attackers may exploit this vulnerability to execute arbitrary machine code in the context of the victim trying to access a malicious Jet database file.
This vulnerability is reported to reside in the 'msjet40.dll' library, version 4.00.8618.0. Older versions may also be affected. The 'msjetole40.dll' OLE (Object Linking and Embedding) library is reportedly immune to this vulnerability.
The Backdoor.Hesive trojan is reported to employ this vulnerability to install itself on vulnerable computers. Please see the web reference for more information.
Exploit / POC
Microsoft Jet Database Engine Malformed Database File Buffer Overflow Vulnerability
The following exploits have been made available:
The following exploits have been made available:
Solution / Fix
Microsoft Jet Database Engine Malformed Database File Buffer Overflow Vulnerability
Solution:
Microsoft Security Bulletin MS08-028 addresses this issue. Please see the references for more information.
Microsoft JET 4.0 SP1
Microsoft JET 4.0 SP4
Microsoft JET 4.0
Microsoft JET 4.0 SP5
Microsoft JET 4.0 SP2
Microsoft JET 4.0 SP7
Microsoft JET 4.0 SP3
Microsoft JET 4.0 SP6
Solution:
Microsoft Security Bulletin MS08-028 addresses this issue. Please see the references for more information.
Microsoft JET 4.0 SP1
-
Microsoft Security Update for Windows 2000 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=0de12d09-e675 -4cf0-bc6f-e42eeb4784a1 -
Microsoft Security Update for Windows Server 2003 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=86e3ed62-98f7 -46ec-96ab-5e8c123b1288&displaylang=en -
Microsoft Security Update for Windows Server 2003 for IB Systems (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3452119b-ba4c -4272-82ec-97396b2c2c3d&displaylang=en -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=5dfc867b-74b7 -4818-9fc2-d71e7c9d2e38&displaylang=en -
Microsoft Security Update for Windows XP (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3247433f-0aa9 -49b8-9e40-c5463a95bcff&displaylang=en -
Microsoft Security Update for Windows XP x64 Edition (KB950749) - English
http://www.microsoft.com/downloads/details.aspx?familyid=4915ebc4-5e7b -493e-b8c4-321d40d9a701&displaylang=en
Microsoft JET 4.0 SP4
-
Microsoft Security Update for Windows 2000 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=0de12d09-e675 -4cf0-bc6f-e42eeb4784a1 -
Microsoft Security Update for Windows Server 2003 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=86e3ed62-98f7 -46ec-96ab-5e8c123b1288&displaylang=en -
Microsoft Security Update for Windows Server 2003 for IB Systems (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3452119b-ba4c -4272-82ec-97396b2c2c3d&displaylang=en -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=5dfc867b-74b7 -4818-9fc2-d71e7c9d2e38&displaylang=en -
Microsoft Security Update for Windows XP (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3247433f-0aa9 -49b8-9e40-c5463a95bcff&displaylang=en -
Microsoft Security Update for Windows XP x64 Edition (KB950749) - English
http://www.microsoft.com/downloads/details.aspx?familyid=4915ebc4-5e7b -493e-b8c4-321d40d9a701&displaylang=en
Microsoft JET 4.0
-
Microsoft Security Update for Windows 2000 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=0de12d09-e675 -4cf0-bc6f-e42eeb4784a1 -
Microsoft Security Update for Windows Server 2003 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=86e3ed62-98f7 -46ec-96ab-5e8c123b1288&displaylang=en -
Microsoft Security Update for Windows Server 2003 for IB Systems (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3452119b-ba4c -4272-82ec-97396b2c2c3d&displaylang=en -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=5dfc867b-74b7 -4818-9fc2-d71e7c9d2e38&displaylang=en -
Microsoft Security Update for Windows XP (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3247433f-0aa9 -49b8-9e40-c5463a95bcff&displaylang=en -
Microsoft Security Update for Windows XP x64 Edition (KB950749) - English
http://www.microsoft.com/downloads/details.aspx?familyid=4915ebc4-5e7b -493e-b8c4-321d40d9a701&displaylang=en
Microsoft JET 4.0 SP5
-
Microsoft Security Update for Windows 2000 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=0de12d09-e675 -4cf0-bc6f-e42eeb4784a1 -
Microsoft Security Update for Windows Server 2003 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=86e3ed62-98f7 -46ec-96ab-5e8c123b1288&displaylang=en -
Microsoft Security Update for Windows Server 2003 for IB Systems (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3452119b-ba4c -4272-82ec-97396b2c2c3d&displaylang=en -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=5dfc867b-74b7 -4818-9fc2-d71e7c9d2e38&displaylang=en -
Microsoft Security Update for Windows XP (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3247433f-0aa9 -49b8-9e40-c5463a95bcff&displaylang=en -
Microsoft Security Update for Windows XP x64 Edition (KB950749) - English
http://www.microsoft.com/downloads/details.aspx?familyid=4915ebc4-5e7b -493e-b8c4-321d40d9a701&displaylang=en
Microsoft JET 4.0 SP2
-
Microsoft Security Update for Windows 2000 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=0de12d09-e675 -4cf0-bc6f-e42eeb4784a1 -
Microsoft Security Update for Windows Server 2003 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=86e3ed62-98f7 -46ec-96ab-5e8c123b1288&displaylang=en -
Microsoft Security Update for Windows Server 2003 for IB Systems (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3452119b-ba4c -4272-82ec-97396b2c2c3d&displaylang=en -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=5dfc867b-74b7 -4818-9fc2-d71e7c9d2e38&displaylang=en -
Microsoft Security Update for Windows XP (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3247433f-0aa9 -49b8-9e40-c5463a95bcff&displaylang=en -
Microsoft Security Update for Windows XP x64 Edition (KB950749) - English
http://www.microsoft.com/downloads/details.aspx?familyid=4915ebc4-5e7b -493e-b8c4-321d40d9a701&displaylang=en
Microsoft JET 4.0 SP7
-
Microsoft Security Update for Windows 2000 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=0de12d09-e675 -4cf0-bc6f-e42eeb4784a1 -
Microsoft Security Update for Windows Server 2003 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=86e3ed62-98f7 -46ec-96ab-5e8c123b1288&displaylang=en -
Microsoft Security Update for Windows Server 2003 for IB Systems (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3452119b-ba4c -4272-82ec-97396b2c2c3d&displaylang=en -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=5dfc867b-74b7 -4818-9fc2-d71e7c9d2e38&displaylang=en -
Microsoft Security Update for Windows XP (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3247433f-0aa9 -49b8-9e40-c5463a95bcff&displaylang=en -
Microsoft Security Update for Windows XP x64 Edition (KB950749) - English
http://www.microsoft.com/downloads/details.aspx?familyid=4915ebc4-5e7b -493e-b8c4-321d40d9a701&displaylang=en
Microsoft JET 4.0 SP3
-
Microsoft Security Update for Windows 2000 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=0de12d09-e675 -4cf0-bc6f-e42eeb4784a1 -
Microsoft Security Update for Windows Server 2003 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=86e3ed62-98f7 -46ec-96ab-5e8c123b1288&displaylang=en -
Microsoft Security Update for Windows Server 2003 for IB Systems (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3452119b-ba4c -4272-82ec-97396b2c2c3d&displaylang=en -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=5dfc867b-74b7 -4818-9fc2-d71e7c9d2e38&displaylang=en -
Microsoft Security Update for Windows XP (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3247433f-0aa9 -49b8-9e40-c5463a95bcff&displaylang=en -
Microsoft Security Update for Windows XP x64 Edition (KB950749) - English
http://www.microsoft.com/downloads/details.aspx?familyid=4915ebc4-5e7b -493e-b8c4-321d40d9a701&displaylang=en
Microsoft JET 4.0 SP6
-
Microsoft Security Update for Windows 2000 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=0de12d09-e675 -4cf0-bc6f-e42eeb4784a1 -
Microsoft Security Update for Windows Server 2003 (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=86e3ed62-98f7 -46ec-96ab-5e8c123b1288&displaylang=en -
Microsoft Security Update for Windows Server 2003 for IB Systems (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3452119b-ba4c -4272-82ec-97396b2c2c3d&displaylang=en -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=5dfc867b-74b7 -4818-9fc2-d71e7c9d2e38&displaylang=en -
Microsoft Security Update for Windows XP (KB950749)
http://www.microsoft.com/downloads/details.aspx?familyid=3247433f-0aa9 -49b8-9e40-c5463a95bcff&displaylang=en -
Microsoft Security Update for Windows XP x64 Edition (KB950749) - English
http://www.microsoft.com/downloads/details.aspx?familyid=4915ebc4-5e7b -493e-b8c4-321d40d9a701&displaylang=en
References
Microsoft Jet Database Engine Malformed Database File Buffer Overflow Vulnerability
References:
References: