CVE-2014-3802

msdia.dll in Microsoft Debug Interface Access (DIA) SDK, as distributed in Microsoft Visual Studio before 2013, does not properly validate an unspecified variable before use in calculating a dynamic-call address, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDB file.
References
Link Resource
http://zerodayinitiative.com/advisories/ZDI-14-129/ Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/67398 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:visual_studio:2003:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:2005:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:2010:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:2010:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:2002:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:debug_interface_access_software_development_kit:-:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:*:*:*:*:*:*:*:*

Information

Published : 2014-05-20 16:55

Updated : 2016-09-09 08:08


NVD link : CVE-2014-3802

Mitre link : CVE-2014-3802


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

microsoft

  • visual_studio
  • debug_interface_access_software_development_kit