Oval Definition:oval:org.mitre.oval:def:5997
Revision Date:2015-08-10Version:13
Title:Microsoft PICT Filter Parsing Vulnerability
Description:Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows remote attackers to execute arbitrary code via a crafted PICT file with an invalid bits_per_pixel field, aka the "PICT Filter Parsing Vulnerability," a different vulnerability than CVE-2008-3018.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2008-3021
Platform(s):Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows XP
Product(s):Microsoft Office 2000
Microsoft Office 2003
Microsoft Office Converter Pack
Microsoft Office Project 2002
Microsoft Office XP
Microsoft Works 8
Definition Synopsis
  • Vulnerable Office XP/2000/2003 / Project 2002 SP1
  • Microsoft Office 2000 is installed
  • OR Microsoft Office XP is installed
  • OR Microsoft Project 2002 SP1 is installed
  • OR Microsoft Office Converter Pack is installed
  • OR Microsoft Office 2003 is installed
  • AND Gifimp32.flt version is less than 2003.1100.8165.0
  • BACK