Proventia Server IPS for Linux technology, Proventia Network IPS, Proventia Desktop, Proventia-G 1.1 and earlier, Proventia Network MFS, Proventia Server IPS for Microsoft Windows technology, RealSecure Network, RealSecure Server Sensor, BlackICE Server Protection, BlackICE PC Protection:
This signature detects a specially-crafted file that can result in the execution of arbitrary code.
High
Proventia Server IPS for Linux technology: 27.070, Proventia Network IPS: XPU 27.070, Proventia Desktop: 2080, Proventia-G 1.1 and earlier: XPU 27.070, Proventia Network MFS: XPU 27.070, Proventia Server IPS for Microsoft Windows technology: 1.0.914.2080, RealSecure Network: XPU 27.070, RealSecure Server Sensor: XPU 27.070, BlackICE Server Protection: 3.6.cqn, BlackICE PC Protection: 3.6cqn
Microsoft Windows Vista, Microsoft Windows 2003 Server: SP2, Microsoft Windows 2003 Server: SP2 Itanium, Microsoft Windows XP: SP2 Professional x64, Microsoft Windows Vista: x64, Microsoft Windows 2003 Server: SP2 x64, Microsoft Office: 2004, Microsoft Visual Basic: 6.0 SP6, Microsoft Windows 2000: SP4, Microsoft Windows 2003 Server: x64, Microsoft Windows XP: Professional x64, Microsoft Windows 2003 Server: SP1, Microsoft Windows 2003 Server: SP1 Itanium, Microsoft Windows XP: SP2
Unauthorized Access Attempt
An application is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges.
Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS08-008. See References.
Microsoft Security Bulletin MS08-008
Vulnerability in OLE Automation Could Allow Remote Code Execution (947890)
http://www.microsoft.com/technet/security/bulletin/ms08-008.mspx
IBM Internet Security Systems X-Force Database
Microsoft Windows OLE script request buffer overflow
http://xforce.iss.net/xforce/xfdb/40043
Nortel BULLETIN ID: 2008008631, Rev 1
Nortel Response to Microsoft Security Bulletin MS08-008
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=691325
ISS X-Force
OLE stream buffer overflow
http://www.iss.net/security_center/static/33226.php
CVE
CVE-2007-0065
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0065