Vulnerability Description
Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Jet | 4.0.8618.0 |
| Microsoft | Office | 2003 |
| Microsoft | Windows 2000 | All versions |
| Microsoft | Windows 2003 Server | All versions |
| Microsoft | Windows Nt | 4.0 |
| Microsoft | Windows Xp | All versions |
Related Weaknesses (CWE)
References
- http://dvlabs.tippingpoint.com/advisory/TPTI-08-04
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-November/058531.html
- http://marc.info/?l=bugtraq&m=121129490723574&w=2
- http://ruder.cdut.net/blogview.asp?logID=227
- http://securityreason.com/securityalert/3376
- http://www.kb.cert.org/vuls/id/936529US Government Resource
- http://www.securityfocus.com/archive/1/483797/100/0/threaded
- http://www.securityfocus.com/archive/1/483858/100/100/threaded
- http://www.securityfocus.com/archive/1/483887/100/100/threaded
- http://www.securityfocus.com/archive/1/483888/100/100/threaded
- http://www.securityfocus.com/archive/1/492019/100/0/threaded
- http://www.securityfocus.com/bid/26468
- http://www.securityfocus.com/bid/28398
- http://www.securitytracker.com/id?1018976
- http://www.us-cert.gov/cas/techalerts/TA08-134A.htmlUS Government Resource
FAQ
What is CVE-2007-6026?
CVE-2007-6026 is a vulnerability with a CVSS score of 9.3 (HIGH). Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary cod...
How severe is CVE-2007-6026?
CVE-2007-6026 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-6026?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Jet, Microsoft Office, Microsoft Windows 2000, Microsoft Windows 2003 Server, Microsoft Windows Nt.