CVE-2008-0109

Microsoft Office Word 2000 SP3, XP SP3, 2003 SP2, and Word Viewer 2003 - Remote Code Execution via Crafted FIB Fields

Title source: llm
STIX 2.1

Description

Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.

References (10)

Core 10
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0511/references
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27656
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28901
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=120361015026386&w=2
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/692417
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/488071/100/0/threaded
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA08-043C.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019374
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5073

Scores

EPSS 0.3087
EPSS Percentile 98.1%

Details

CWE
CWE-399
Status published
Products (4)
microsoft/office 2000 sp3
microsoft/office 2003 (2 CPE variants)
microsoft/office xp sp3
microsoft/word
Published Feb 12, 2008
Tracked Since Feb 18, 2026