René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

115 lines
3.8 KiB
JSON

{
"id": "CVE-2011-1972",
"sourceIdentifier": "secure@microsoft.com",
"published": "2011-08-10T21:55:01.860",
"lastModified": "2018-10-12T22:01:13.503",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka \"pStream Release RCE Vulnerability.\""
},
{
"lang": "es",
"value": "Microsoft Visio 2003 SP3, 2007 SP2 y 2010 Gold y SP1 no valida adecuadamente los objetos en memoria durante el an\u00e1lisis sint\u00e1ctico del fichero Visio, esto permite a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n mediante un fichero manipulado. Tambi\u00e9n se conoce como \"Vulnerabildiad en pStream Release RCE\"."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 9.3
},
"baseSeverity": "HIGH",
"exploitabilityScore": 8.6,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2003:sp3:*:*:*:*:*:*",
"matchCriteriaId": "553ADEFC-11EC-4E29-8A95-4AF59DB6CEAE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2007:sp2:*:*:*:*:*:*",
"matchCriteriaId": "E822A55C-0440-4622-9284-A5DF70D49C63"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2010:*:x32:*:*:*:*:*",
"matchCriteriaId": "6FD08D8C-C7B8-41CB-8F21-F894704330B0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2010:*:x64:*:*:*:*:*",
"matchCriteriaId": "C029E0B6-9E53-409A-BAFF-5A2F17AB14AD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2010:sp1:x32:*:*:*:*:*",
"matchCriteriaId": "BB6C963E-46DA-422C-9DE7-B0536F001C5E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:microsoft:visio:2010:sp1:x64:*:*:*:*:*",
"matchCriteriaId": "1AA1633F-11EA-42E1-A4C7-7334E8EF8486"
}
]
}
]
}
],
"references": [
{
"url": "http://www.us-cert.gov/cas/techalerts/TA11-221A.html",
"source": "secure@microsoft.com",
"tags": [
"US Government Resource"
]
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-060",
"source": "secure@microsoft.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12852",
"source": "secure@microsoft.com"
}
]
}