New Search

Integer Overflow Vulnerability

oval:org.mitre.oval:def:6127

Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file containing a crafted record type for "collaboration information for different slides" that contains a field that specifies a large number of records which triggers an under-allocated buffer and a heap-based buffer overflow aka "Integer Overflow Vulnerability."

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows Vista
  • Microsoft Windows XP
  • Microsoft Windows 2000
  • Microsoft Windows Server 2003
Class:
vulnerability
Reference(s):
  • CVE-2009-0221
Product(s):
  • Microsoft Office PowerPoint 2003 Service Pack 3
  • Microsoft Office PowerPoint 2002 Service Pack 3