Oval Definition:
oval:org.mitre.oval:def:5381
Revision Date
:
2011-11-14
Version
:
22
Title
:
Mini-Redirector Heap Overflow Vulnerability
Description
:
Heap-based buffer overflow in the WebDAV Mini-Redirector in Microsoft Windows XP SP2, Server 2003 SP1 and SP2, and Vista allows remote attackers to execute arbitrary code via a crafted WebDAV response.
Family
:
windows
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2008-0080
Platform(s)
:
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows XP
Product(s)
:
Definition Synopsis
Vulnerable Windows XP SP2
Microsoft Windows XP SP2 or later is installed
AND
the version of mrxdav.sys is less than 5.1.2600.3276
OR
Vulnerable Windows XP x64 SP1/Server 2003 x64 SP1
Windows XP x64 SP1/Server 2003 x64 SP1
Microsoft Windows XP Professional x64 Edition SP1 is installed
OR
Microsoft Windows Server 2003 SP1 (x64) is installed
AND
the version of mrxdav.sys is less than 5.2.3790.3075
OR
Vulnerable Windows XP x64 SP2/Server 2003 x64 SP2
Windows XP x64 SP2/Server 2003 x64 SP2
Microsoft Windows XP x64 Edition SP2 is installed
OR
Microsoft Windows Server 2003 SP2 (x64) is installed
AND
the version of mrxdav.sys is less than 5.2.3790.4221
OR
Vulnerable Windows Server 2003 SP1 (x86)/(ia-64)
Windows Server 2003 SP1 (x86)/(ia-64)
Microsoft Windows Server 2003 SP1 (x86) is installed
OR
Microsoft Windows Server 2003 SP1 for Itanium is installed
AND
the version of mrxdav.sys is less than 5.2.3790.3060
OR
Vulnerable Windows Server 2003 SP2 (x86)/(ia-64)
Windows Server 2003 SP2 (x86)/(ia-64)
Microsoft Windows Server 2003 SP2 (x86) is installed
OR
Microsoft Windows Server 2003 (ia64) SP2 is installed
AND
the version of mrxdav.sys is less than 5.2.3790.4206
OR
Vulnerable Windows Vista (32-bit)/(x64)
Windows Vista (32-bit)/(x64)
Microsoft Windows Vista (32-bit) is installed
OR
Microsoft Windows Vista x64 Edition is installed
AND
Check for LDR/GDR
the version of mrxdav.sys is less than 6.0.6000.16626
OR
Check for LDR
Check if version of mrxdav.sys is greater than or equal to 6.0.6000.20000
AND
Check if version of mrxdav.sys is less than 6.0.6000.20751
BACK