int(748)

Vulnerability Bulletins


Desbordamiento de búfer en Microsoft Jet Database Engine

Vulnerability classification

Property Value
Confidence level Oficial
Impact Compromiso Root
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio exotico

System information

Property Value
Affected manufacturer Microsoft
Affected software Microsoft Jet Database Engine 4.0

Description

Se ha descubierto una vulnerabilidad de desbordamiento de búfer en la versión 4.0 de Microsoft Jet Database Engine. La explotación de esta vulnerabilidad podría permitir a un atacante remoto la ejecución remota de código en un sistema donde este ejecutándose Microsoft Jet Database Engine mediante una petición especialmente diseñada a una base de datos que le llegue mediante una aplicación que utilice Jet Database Engine en la máquina afectada.

El boletín MS08-028 sustituye al MS04-014.

Solution



Actualización de software

Microsoft Jet Database Engine 4.0
Microsoft Windows NT Workstation 4.0 Service Pack 6a
http://www.microsoft.com/downloads/details.aspx?FamilyId=7678462A-52EC-48D5-9AEB-46EC4CC053C7
Microsoft Windows NT Server 4.0 Service Pack 6a
http://www.microsoft.com/downloads/details.aspx?FamilyId=7678462A-52EC-48D5-9AEB-46EC4CC053C7
Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6
http://www.microsoft.com/downloads/details.aspx?FamilyId=7678462A-52EC-48D5-9AEB-46EC4CC053C7
Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft Windows 2000 Service Pack 4
http://www.microsoft.com/downloads/details.aspx?FamilyId=EA17D1CB-075E-4B63-BC45-06EBBF41C6B5
Microsoft Windows XP, Microsoft Windows XP Service Pack 1
http://www.microsoft.com/downloads/details.aspx?FamilyId=EA17D1CB-075E-4B63-BC45-06EBBF41C6B5
Microsoft Windows XP 64-Bit Edition Service Pack 1
http://www.microsoft.com/downloads/details.aspx?FamilyId=B487610D-806C-4289-BE70-92F7D2337E17
Microsoft Windows XP 64-Bit Edition Version 2003
http://www.microsoft.com/downloads/details.aspx?FamilyId=E4E0EB80-7395-4C07-BC1D-B187DE541BC2
Microsoft Windows Server 2003
http://www.microsoft.com/downloads/details.aspx?FamilyId=216D708B-3A55-4B50-8AD2-BFF06B668CBB
Microsoft Windows Server 2003 64-Bit Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=E4E0EB80-7395-4C07-BC1D-B187DE541BC2

Standar resources

Property Value
CVE CAN-2004-0197
BID

Other resources

Microsoft Security Bulletin (MS04-014)
http://www.microsoft.com/technet/security/Bulletin/MS04-014.mspx

Microsoft Security Bulletin (MS08-028)
http://www.microsoft.com/technet/security/Bulletin/ms08-028.mspx

Version history

Version Comments Date
1.0 Aviso emitido 2004-04-14
1.1 Aviso emitido por Microsoft (MS08-028). Descripción actualizada. 2008-05-14
Ministerio de Defensa
CNI
CCN
CCN-CERT