漏洞信息详情
Microsoft Excel公式解析远程代码执行漏洞
- CNNVD编号:CNNVD-200911-133
- 危害等级: 超危
- CVE编号: CVE-2009-3131
- 漏洞类型: 代码注入
- 发布时间: 2009-11-11
- 威胁类型: 远程
- 更新时间: 2009-11-11
- 厂 商: microsoft
- 漏洞来源: Nicolas Joly of VU...
漏洞简介
Microsoft Office Excel,Mac Office,Mac Open XML文件格式化转换器,Office Excel Viewer,Office Excel Viewer以及Word,Excel和PowerPoint文件格式化和Office兼容包没有正确的解析Excel文件格式化,远程攻击者可以借助一个带有特制的内嵌于单元中的公式的电子表格,执行任意代码。又称\"Excel公式解析内存破坏漏洞\"。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Microsoft Office 2008 for Mac 0
Microsoft Microsoft Office 2008 for Mac 12.2.3 Update
http://www.microsoft.com/downloads/details.aspx?FamilyID=b84fe57d-ddda
-451e-9ead-69e10aee7928
Microsoft Excel 2003 SP3
Microsoft Security Update for Microsoft Office Excel 2003 (KB973475)
http://www.microsoft.com/downloads/details.aspx?familyid=6a6a0f5d-17dc
-4a34-b9a0-0774aa287ba5
Microsoft Office Compatibility Pack 2007 SP2
Microsoft Security Update for the 2007 Microsoft Office System (KB973704)
http://www.microsoft.com/downloads/details.aspx?familyid=c4c92d2e-e87d
-446f-8d3e-8f4be10c70aa
Microsoft Office Compatibility Pack 2007 SP1
Microsoft Security Update for the 2007 Microsoft Office System (KB973704)
http://www.microsoft.com/downloads/details.aspx?familyid=c4c92d2e-e87d
-446f-8d3e-8f4be10c70aa
Microsoft Open XML File Format Converter for Mac 0
Microsoft Open XML File Format Converter for Mac 1.1.3
http://www.microsoft.com/downloads/details.aspx?FamilyID=4dd4bc05-1217
-497e-8f65-4347f2544ed6
Microsoft Office Excel Viewer SP1
Microsoft Security Update for Microsoft Office Excel Viewer (KB973707)
http://www.microsoft.com/downloads/details.aspx?familyid=fb36df5e-ebef
-46bf-9edd-67f2c76dbdb3
Microsoft Excel 2002 SP3
Microsoft Security Update for Microsoft Excel 2002 (KB973471)
http://www.microsoft.com/downloads/details.aspx?familyid=5672c8fc-8509
-4962-ad86-ebc0f2575043
Microsoft Excel 2007 SP2
Microsoft Security Update for Microsoft Office Excel 2007 (KB973593)
http://www.microsoft.com/downloads/details.aspx?familyid=322b24ca-aff6
-4ca0-acf1-440cae0f9693
Microsoft Excel 2007 SP1
Microsoft Security Update for Microsoft Office Excel 2007 (KB973593)
http://www.microsoft.com/downloads/details.aspx?familyid=322b24ca-aff6
-4ca0-acf1-440cae0f9693
Microsoft Office 2004 for Mac 0
Microsoft Microsoft Office 2004 for Mac 11.5.6 Update
http://www.microsoft.com/downloads/details.aspx?FamilyID=8f115b1c-1e28
-4ecf-937c-99c4b60c7c8e
Microsoft Excel Viewer 2003 SP3
Microsoft Security Update for Microsoft Office Excel Viewer 2003 (KB973484)
http://www.microsoft.com/downloads/details.aspx?familyid=19151e22-5642
-456c-bd39-298574369cdb
Microsoft Office Excel Viewer 2003 SP3
Microsoft Security Update for Microsoft Office Excel Viewer 2003 (KB973484)
http://www.microsoft.com/downloads/details.aspx?familyid=19151e22-5642
-456c-bd39-298574369cdb
Microsoft Office Excel Viewer SP2
Microsoft Security Update for Microsoft Office Excel Viewer (KB973707)
http://www.microsoft.com/downloads/details.aspx?familyid=fb36df5e-ebef
-46bf-9edd-67f2c76dbdb3
参考网址
来源: US-CERT
名称: TA09-314A
链接:http://www.us-cert.gov/cas/techalerts/TA09-314A.HTML
来源: MS
名称: MS09-067
链接:http://www.microsoft.com/technet/security/Bulletin/MS09-067.mspx
受影响实体
- Microsoft Excel_viewer:2003:Sp3
- Microsoft Open_xml_file_format_converter:Mac
- Microsoft Office:2008:Mac
- Microsoft Office:2004:Mac
- Microsoft Excel_viewer:Sp1
补丁
暂无
评论