VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
JVN#62211338     ( Technical Cyber Security Alert TA09-251A | CVE-2009-2498 | CVE-2009-2499 | JPCERT-AT-2009-0018 | JVNDB-2009-000059 )
Microsoft Windows におけるバッファオーバーフローの脆弱性
http://jvn.jp/jp/JVN62211338/index.html

Microsoft Windows の Windows Media Format Runtime には、特定のファイルの解析に起因するバッファオーバーフローの脆弱性が存在します。




About This Analysis Information
Analysis Information Provider:
JPCERT/CC
First Published:
2009-09-09
Source Information Category:
Advisory, Alert
Last Updated:
2009-09-09




Affected Product Tags
cpe:/o:microsoft:windows_2000     (Microsoft Windows 2000)
cpe:/o:microsoft:windows_server:2003     (Microsoft Windows Server 2003)
cpe:/o:microsoft:windows_server:2008     (Microsoft Windows Server 2008)
cpe:/o:microsoft:windows_server_2003:::x64     (Microsoft Windows Server 2003 x64)
cpe:/o:microsoft:windows_server_2008:::x64     (Windows Server 2008 for 64-bit Systems)
cpe:/o:microsoft:windows_vista     (Microsoft Windows Vista)
cpe:/o:microsoft:windows_vista:::x64     (Microsoft Windows Vista x64)
cpe:/o:microsoft:windows_xp     (Microsoft Windows XP)
lapt:/o:microsoft:windows_xp:::professional_x64     ( Microsoft Windows XP Professional x64 Edition)
 


Vulnerability Analysis Results
[Information Source Reliability] [?]
Low [?]

Medium [?]
X High [?]

[Impact Level] [?]
Low [?]

Low-Medium [?]
X Medium-High [?]
High [?]

[Access Required] [?]
Physical [?]

Local [?]
Non-routed [?]
X Routed [?]

[Authentication] [?]
Privileged [?]

Standard [?]
Limited [?]
X None or Unnecessary [?]

[User Interaction Required] [?]
Complex [?]

X Simple [?]
None [?]

[Technical Difficulty] [?]
High [?]

Medium-High [?]
X Low-Medium [?]
Low [?]

[Availability of Remediation] [?]
X Official Patch [?]

Official Workaround [?]
Unofficial Patch [?]
None [?]

[Incident Activity] [?]
None [?]

Exploit or PoC [?]
Activity Observed [?]

Alternatives
CERT Advisory Technical Cyber Security Alert TA09-251A Microsoft Updates for Multiple Vulnerabilities
Microsoft has released updates to address vulnerabilities in Microsoft Windows, and Windows Server




Common Vulnerabilities and Exposures (CVE) CVE-2009-2498




Common Vulnerabilities and Exposures (CVE) CVE-2009-2499




JPCERT AT JPCERT-AT-2009-0018 2009年9月 Microsoft セキュリティ情報 (緊急 5件) に関する注意喚起
Microsoft 社から 2009年9月のセキュリティ情報が公開されました。本情報 には、深刻度が「緊急」のセキュリティ更新プログラムが 5件含まれています。




JVN iPedia JVNDB-2009-000059 Microsoft Windows におけるバッファオーバーフローの脆弱性
Microsoft Windows の Windows Media Format Runtime には、特定のファイルの解析に起因するバッファオーバーフローの脆弱性が存在します。








References

Copyright © 2009 JPCERT/CC All Rights Reserved.