FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-2493

This CVE name corresponds to:

Entered Topic
2010-02-25 openoffice.org -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-2493
Phase Assigned(20090717)

Description

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."

References

Source Reference
MISC http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx
CONFIRM http://www.adobe.com/support/security/advisories/apsa09-04.html
CONFIRM http://www.adobe.com/support/security/bulletins/apsb09-11.html
CONFIRM http://www.adobe.com/support/security/bulletins/apsb09-13.html
CONFIRM http://www.adobe.com/support/security/bulletins/apsb09-10.html
CONFIRM http://www.openoffice.org/security/cves/CVE-2009-2493.html
CONFIRM http://www.novell.com/support/viewContent.do?externalId=7004997&sliceId=1
HP HPSBMA02488
HP SSRT100013
MS MS09-035
MS MS09-037
MS MS09-055
MS MS09-060
MS MS09-072
SUNALERT 264648
SUNALERT 266108
SUNALERT 1020775
SUSE SUSE-SA:2009:053
CERT TA09-195A
CERT TA09-223A
CERT TA09-286A
CERT TA09-342A
OVAL oval:org.mitre.oval:def:6245
OVAL oval:org.mitre.oval:def:6304
OVAL oval:org.mitre.oval:def:6421
OVAL oval:org.mitre.oval:def:6473
OVAL oval:org.mitre.oval:def:6621
OVAL oval:org.mitre.oval:def:6716
SECUNIA 36187
SECUNIA 36374
SECUNIA 38568
SECUNIA 36746
SECUNIA 35967
SECUNIA 41818
VUPEN ADV-2009-2034
VUPEN ADV-2009-2232
VUPEN ADV-2010-0366