Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:DL:WMF-IO

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Microsoft Windows GDIplus WMF Integer Overflow

Release Date

2010/10/11

Update Number

1789

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Microsoft Windows GDIplus WMF Integer Overflow


This signature detects attempts to exploit a known vulnerability in the Microsoft Windows WMF parser. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the user.

Extended Description

Microsoft GDI+ is prone to a remote code-execution vulnerability because the vector graphics link library improperly processes WMF image files. An attacker could exploit this issue to execute arbitrary code with the privileges of the currently logged-in user. Failed exploit attempts may crash applications that use the library.

Affected Products

  • Microsoft Excel Viewer
  • Microsoft Expression Web 2
  • Microsoft Expression Web
  • Microsoft Forefront Client Security 1.0
  • Microsoft Groove 2007 SP1
  • Microsoft Groove 2007
  • Microsoft Internet Explorer 6.0
  • Microsoft Internet Explorer 6.0 SP1
  • Microsoft Office 2003 SP1
  • Microsoft Office 2003 SP2
  • Microsoft Office 2003 SP3
  • Microsoft Office 2003
  • Microsoft Office 2007 SP1
  • Microsoft Office 2007 SP2
  • Microsoft Office 2007
  • Microsoft Office Compatibility Pack 2007 SP1
  • Microsoft Office Compatibility Pack 2007 SP2
  • Microsoft Office Compatibility Pack 2007
  • Microsoft Office Excel Viewer 2003 SP3
  • Microsoft Office Excel Viewer 2003
  • Microsoft Office XP SP1
  • Microsoft Office XP SP2
  • Microsoft Office XP SP3
  • Microsoft Office XP
  • Microsoft Platform SDK Redistributable: GDI+
  • Microsoft PowerPoint Viewer 2007 SP1
  • Microsoft PowerPoint Viewer 2007 SP2
  • Microsoft PowerPoint Viewer 2007
  • Microsoft Project 2002 SP1
  • Microsoft Project 2002
  • Microsoft Project 2002
  • Microsoft Report Viewer 2005 SP1
  • Microsoft Report Viewer 2008 SP1
  • Microsoft Report Viewer 2008
  • Microsoft SQL Server 2000 Reporting Services SP2
  • Microsoft SQL Server 2005 SP1
  • Microsoft SQL Server 2005 SP2
  • Microsoft SQL Server 2005 SP3
  • Microsoft SQL Server 2005
  • Microsoft SQL Server 2005 Express Edition SP1
  • Microsoft SQL Server 2005 Express Edition SP2
  • Microsoft SQL Server 2005 Express Edition
  • Microsoft SQL Server 2005 Itanium Edition SP1
  • Microsoft SQL Server 2005 Itanium Edition SP2
  • Microsoft SQL Server 2005 Itanium Edition SP3
  • Microsoft SQL Server 2005 Itanium Edition
  • Microsoft SQL Server 2005 x64 Edition SP1
  • Microsoft SQL Server 2005 x64 Edition SP2
  • Microsoft SQL Server 2005 x64 Edition SP3
  • Microsoft Visio 2002 SP1
  • Microsoft Visio 2002 SP2
  • Microsoft Visio 2002
  • Microsoft Visio 2002 Professional SP2
  • Microsoft Visio Viewer SP2
  • Microsoft Visual FoxPro 8.0
  • Microsoft Visual FoxPro 8.0 SP1
  • Microsoft Visual FoxPro 9.0 SP1
  • Microsoft Visual FoxPro 9.0 SP2
  • Microsoft Visual Studio 2005 SP1
  • Microsoft Visual Studio 2005
  • Microsoft Visual Studio 2005 Professional Edition
  • Microsoft Visual Studio 2005 Standard Edition
  • Microsoft Visual Studio 2005 Team Edition
  • Microsoft Visual Studio 2005 Team Edition for Architects
  • Microsoft Visual Studio 2005 Team Edition for Developers
  • Microsoft Visual Studio 2005 Team Edition for Testers
  • Microsoft Visual Studio 2008 SP1
  • Microsoft Visual Studio 2008
  • Microsoft Visual Studio .NET 2003 SP1
  • Microsoft Visual Studio .NET 2003
  • Microsoft Visual Studio .NET 2003
  • Microsoft Windows XP
  • Microsoft Windows XP Embedded SP1
  • Microsoft Windows XP Embedded SP2
  • Microsoft Windows XP Embedded SP3
  • Microsoft Windows XP Embedded
  • Microsoft Windows XP Gold
  • Microsoft Windows XP Home SP1
  • Microsoft Windows XP Home SP2
  • Microsoft Windows XP Home SP3
  • Microsoft Windows XP Home
  • Microsoft Windows XP Media Center Edition SP1
  • Microsoft Windows XP Media Center Edition SP2
  • Microsoft Windows XP Media Center Edition SP3
  • Microsoft Windows XP Media Center Edition
  • Microsoft Windows XP Professional SP1
  • Microsoft Windows XP Professional SP2
  • Microsoft Windows XP Professional SP3
  • Microsoft Windows XP Professional
  • Microsoft Windows XP Tablet PC Edition SP1
  • Microsoft Windows XP Tablet PC Edition SP2
  • Microsoft Windows XP Tablet PC Edition SP3
  • Microsoft Windows XP Tablet PC Edition
  • Microsoft Word Viewer
  • Microsoft Word Viewer 2003 SP3
  • Microsoft Word Viewer 2003
  • Microsoft Works 8.5
  • Nortel Networks CallPilot 1002Rp
  • Nortel Networks CallPilot 200I
  • Nortel Networks CallPilot 201I
  • Nortel Networks CallPilot 702T
  • Nortel Networks CallPilot 703T
  • Nortel Networks Contact Center Administration CCMA 6.0
  • Nortel Networks Contact Center Administration CCMA 7.0
  • Nortel Networks Contact Center Express
  • Nortel Networks Contact Center NCC
  • Nortel Networks Contact Center - TAPI Server
  • Nortel Networks Media Processing Svr 1000 Rel 3.0
  • Nortel Networks Media Processing Svr 500 Rel 3.0
  • Nortel Networks Multimedia Comm Mas
  • Nortel Networks Self-Service - CCSS7
  • Nortel Networks Self-Service CCXML
  • Nortel Networks Self-Service Media Processing Server
  • Nortel Networks Self-Service MPS 100
  • Nortel Networks Self-Service MPS 1000
  • Nortel Networks Self-Service MPS 500
  • Nortel Networks Self-Service Peri Application
  • Nortel Networks Self-Service Peri Workstation
  • Nortel Networks Self-Service Speech Server
  • Nortel Networks Self Service VoiceXML
  • Nortel Networks Self-Service WVADS
  • Nortel Networks Symposium Agent

References

  • BugTraq: 36619
  • CVE: CVE-2009-2500

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out