CVE-2009-2518: Integer Overflow
Published Oct 14, 2009
·Updated
Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) image that triggers memory corruption, aka "Office BMP Integer Overflow Vulnerability."
Affected Software
1 affected component
Microsoft Office=xp-sp3
Event History
Oct 14, 2009
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2518?
CVE-2009-2518 has a severity rating of critical due to its potential for remote code execution.
2
How do I fix CVE-2009-2518?
To fix CVE-2009-2518, you should apply the appropriate Microsoft security update as outlined in their bulletin.
3
Which software versions are affected by CVE-2009-2518?
CVE-2009-2518 affects Microsoft Office XP SP3.
4
What type of vulnerability is CVE-2009-2518?
CVE-2009-2518 is an integer overflow vulnerability that can lead to memory corruption.
5
Can CVE-2009-2518 be exploited through a BMP image?
Yes, CVE-2009-2518 can be exploited by embedding a specially crafted BMP image in an Office document.