PT-2013-2090 · Microsoft · Office Onenote

Christopher Gabriel

·

Published

2013-03-12

·

Updated

2018-10-12

·

CVE-2013-0086

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft OneNote 2010 SP1
Description An information disclosure issue exists due to improper buffer size determination during memory allocation when parsing specially crafted OneNote (.ONE) files. This allows remote attackers to obtain sensitive information.
Recommendations For Microsoft OneNote 2010 SP1, consider avoiding the use of specially crafted OneNote files until a patch is available. As a temporary workaround, restrict access to sensitive information that could be disclosed through this issue.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0086

Affected Products

Office Onenote