Boletines de Vulnerabilidades |
Múltiples vulnerabilidades en Microsoft Word |
|
Clasificación de la vulnerabilidad |
|
| Propiedad | Valor |
| Nivel de Confianza | Oficial |
| Impacto | Obtener acceso |
| Dificultad | Experto |
| Requerimientos del atacante | Acceso remoto sin cuenta a un servicio estandar |
Información sobre el sistema |
|
| Propiedad | Valor |
| Fabricante afectado | Microsoft |
| Software afectado |
Microsoft Word 2000 Service Pack 3 Microsoft Word 2002 Service Pack 3 Microsoft Word 2003 Service Pack 2 Microsoft Word 2003 Service Pack 3 Microsoft Word 2007 Microsoft Word 2007 Service Pack 1 Microsoft Outlook 2007 Microsoft Outlook 2007 Service Pack 1 Microsoft Word Viewer 2003 Microsoft Word Viewer 2003 Service Pack 3 Microsoft Office Compatibility Pack para Word, Excel, y PowerPoint 2007 File Formats Microsoft Office Compatibility Pack para Word, Excel, y PowerPoint 2007 File Formats Service Pack 1 Microsoft Office 2004 para Mac Microsoft Office 2008 para Mac |
Descripción |
|
|
Se han descubierto múltiples vulnerabilidades en Microsoft Word 2000 Service Pack 3, 2002 Service Pack 3, 2003 Service Pack 2 y 3, 2007 y 2007 Service Pack 1, Microsoft Outlook 2007 y 2007 Service Pack 1, Microsoft Word Viewer 2003 y 2003 Service Pack 3, Microsoft Office Compatibility Pack para Word, Excel, y PowerPoint 2007 File Formats y 2007 Service Pack 1, y Microsoft Office 2004 y 2008 para Mac. Las vulnerabilidades son descritas a continuación: - CVE-2008-1091: La vulnerabilidad reside en un error en el cálculo del espacio de memoria cuando se procesan ciertos ficheros ".rtf". Un atacante remoto podría ejecutar código arbitrario mediante un fichero ".rtf" especialmente diseñado con cadenas malformadas. - CVE-2008-1434: La vulnerabilidad reside en un error al manejar la memoria cuando se procesan ciertos valores CSS en ficheros Word. Un atacante remoto podría ejecutar código arbitrario mediante un fichero Word especialmente diseñado. El boletín MS08-026 sustituye a los MS08-009, MS07-024 y MS08-014. El boletín MS08-042 sustituye al MS08-026. El boletín MS08-043 sustituye al MS08-026. |
|
Solución |
|
|
Actualización de software Microsoft (MS08-026) Microsoft Word 2000 / patch office2000-kbB950250 Microsoft Word 2002 / patch officeXP-kb950243-fullfile-enu Microsoft Word 2003 / patch office2003-kb950241-fullfile-enu.exe Microsoft Word 2007 / patch office2007-kb950113-fullfile-x86-glb Microsoft Outlook 2007 / patch Microsoft Outlook 2007 Service Pack 1 / patch Microsoft Word Viewer 2003 / patch office2003-kb950625-fullfile-enu.exe Microsoft Office Compatibility Pack para Word, Excel, y PowerPoint 2007 File Formats / patch office2007-kb951808-fullfile-x86-glb http://www.microsoft.com/downloads Microsoft Office 2004 para Mac 11.4.2 Update http://www.microsoft.com/mac/downloads.mspx?pid=Mactopia_Office2004#viewer Microsoft Office 2008 para Mac Service Pack 1 http://www.microsoft.com/mac/downloads.mspx?pid=Mactopia_Office2008#viewer |
|
Identificadores estándar |
|
| Propiedad | Valor |
| CVE |
CVE-2008-1091 CVE-2008-1434 |
| BID | |
Recursos adicionales |
|
|
Microsoft Security Bulletin (MS08-026) http://www.microsoft.com/technet/security/bulletin/ms08-026.mspx Microsoft Security Bulletin (MS08-042) http://www.microsoft.com/technet/security/bulletin/ms08-042.mspx Microsoft Security Bulletin (MS08-043) http://www.microsoft.com/technet/security/bulletin/ms08-043.mspx |
|
Histórico de versiones |
||
| Versión | Comentario | Fecha |
| 1.0 | Aviso emitido | 2008-05-14 |
| 1.1 | Aviso emitido por Microsoft (MS08-042), aviso emitido por Microsoft (MS08-043) | 2008-08-13 |














