Vulnerability Description
The 64-bit versions of Microsoft Visual C++ 8.0 standard library (MSVCR80.DLL) time functions, including (1) localtime, (2) localtime_s, (3) gmtime, (4) gmtime_s, (5) ctime, (6) ctime_s, (7) wctime, (8) wctime_s, and (9) fstat, trigger an assertion error instead of a NULL pointer or EINVAL when processing a time argument later than Jan 1, 3000, which might allow context-dependent attackers to cause a denial of service (application exit) via large time values. NOTE: it could be argued that this is a design limitation of the functions, and the vulnerability lies with any application that does not validate arguments to these functions. However, this behavior is inconsistent with documentation, which does not list assertions as a possible result of an error condition.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Visual C\+\+ | 2005 |
Related Weaknesses (CWE)
References
- http://msdn2.microsoft.com/en-us/library/a442x3ye%28VS.80%29.aspxPatchVendor Advisory
- http://osvdb.org/33626Broken Link
- http://securityreason.com/securityalert/2237Exploit
- http://www.securityfocus.com/archive/1/459847/100/0/threadedThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32454VDB Entry
- http://msdn2.microsoft.com/en-us/library/a442x3ye%28VS.80%29.aspxPatchVendor Advisory
- http://osvdb.org/33626Broken Link
- http://securityreason.com/securityalert/2237Exploit
- http://www.securityfocus.com/archive/1/459847/100/0/threadedThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32454VDB Entry
FAQ
What is CVE-2007-0842?
CVE-2007-0842 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The 64-bit versions of Microsoft Visual C++ 8.0 standard library (MSVCR80.DLL) time functions, including (1) localtime, (2) localtime_s, (3) gmtime, (4) gmtime_s, (5) ctime, (6) ctime_s, (7) wctime, (...
How severe is CVE-2007-0842?
CVE-2007-0842 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-0842?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Visual C\+\+.