ðòïåëôù
áòèé÷
Security-alerts @yandex-team.ru
óôáôøé
ðåòóïîáìøîïå
ðòïçòáííù
ðéûéôåðéóøíá
> > TITLE: > Microsoft Office String and Property Parsing Vulnerabilities > > SECUNIA ADVISORY ID: > SA21012 > > VERIFY ADVISORY: > http://secunia.com/advisories/21012/ > > CRITICAL: > Highly critical > > IMPACT: > System access > > WHERE: > From remote > > SOFTWARE: > Microsoft Word 2003 Viewer > http://secunia.com/product/5523/ > Microsoft Word 2003 > http://secunia.com/product/4908/ > Microsoft Word 2002 > http://secunia.com/product/2150/ > Microsoft Word 2000 > http://secunia.com/product/2149/ > Microsoft Visio 2003 > http://secunia.com/product/1092/ > Microsoft Visio 2002 > http://secunia.com/product/1091/ > Microsoft Publisher 2003 > http://secunia.com/product/10986/ > Microsoft Access 2000 > http://secunia.com/product/36/ > Microsoft Access 2002 > http://secunia.com/product/35/ > Microsoft Access 2003 > http://secunia.com/product/4904/ > Microsoft Excel 2000 > http://secunia.com/product/3054/ > Microsoft Excel 2002 > http://secunia.com/product/4043/ > Microsoft Excel 2003 > http://secunia.com/product/4970/ > Microsoft Excel Viewer 2003 > http://secunia.com/product/7700/ > Microsoft Frontpage 2000 > http://secunia.com/product/27/ > Microsoft Frontpage 2002 > http://secunia.com/product/26/ > Microsoft Frontpage 2003 > http://secunia.com/product/6997/ > Microsoft InfoPath 2003 > http://secunia.com/product/6463/ > Microsoft Office 2000 > http://secunia.com/product/24/ > Microsoft Office 2003 Professional Edition > http://secunia.com/product/2276/ > Microsoft Office 2003 Small Business Edition > http://secunia.com/product/2277/ > Microsoft Office 2003 Standard Edition > http://secunia.com/product/2275/ > Microsoft Office 2003 Student and Teacher Edition > http://secunia.com/product/2278/ > Microsoft Office 2004 for Mac > http://secunia.com/product/8713/ > Microsoft Office X for Mac > http://secunia.com/product/2610/ > Microsoft Office XP > http://secunia.com/product/23/ > Microsoft OneNote 2003 > http://secunia.com/product/7140/ > Microsoft Outlook 2000 > http://secunia.com/product/33/ > Microsoft Outlook 2002 > http://secunia.com/product/34/ > Microsoft Outlook 2003 > http://secunia.com/product/3292/ > Microsoft PowerPoint 2000 > http://secunia.com/product/3052/ > Microsoft PowerPoint 2002 > http://secunia.com/product/2223/ > Microsoft PowerPoint 2003 > http://secunia.com/product/10985/ > Microsoft Project 2000 > http://secunia.com/product/158/ > Microsoft Project 2002 > http://secunia.com/product/157/ > Microsoft Project 2003 > http://secunia.com/product/3170/ > Microsoft Publisher 2000 > http://secunia.com/product/29/ > Microsoft Publisher 2002 > http://secunia.com/product/30/ > > DESCRIPTION: > Some vulnerabilities have been reported in Microsoft Office, which > can be exploited by malicious people to compromise a user's system. > > 1) An error within the string parsing can be exploited to cause a > buffer overflow when a malicious Office document containing a > malformed string is opened. > > 2) Another error within the string parsing can also be exploited to > corrupt memory when a malicious Office document containing a > malformed string is opened. > > 3) An error within the property handling can be exploited to cause a > buffer overflow when a malicious Office document containing a > malformed property is opened. > > Successful exploitation of the vulnerabilities allows execution of > arbitrary code. > > SOLUTION: > Apply patches. > > Microsoft Office 2003 SP1 / SP2: > http://www.microsoft.com/downloads/details.aspx?FamilyId=1B11A C6B-4A78-4A7B-995F-94738CAFE27F > > Microsoft Office XP SP3: > http://www.microsoft.com/downloads/details.aspx?FamilyId=266C2 87E-A773-4D9C-9736-EEAFB34FF893 > > Microsoft Office 2000 SP3: > http://www.microsoft.com/downloads/details.aspx?FamilyId=776FF 379-0B9D-45D5-8B3C-CF9A4BD25DAE > > Microsoft Project 2002 SP2: > http://www.microsoft.com/downloads/details.aspx?FamilyId=BF9CB FA6-5E91-4AA8-82C1-4C9A92A5B954 > > Microsoft Visio 2002 SP2: > http://www.microsoft.com/downloads/details.aspx?FamilyId=9F67D 75A-B69D-4064-942C-F5515C920E6B > > Microsoft Project 2000 SR1: > http://www.microsoft.com/downloads/details.aspx?FamilyId=5C28E 38A-F323-4006-BEED-A00840CAFBCE > > PROVIDED AND/OR DISCOVERED BY: > 1) Reported by the vendor. > 2) posidron (the vendor also credits Elia Florio, Symantec). > 3) Reported by the vendor. > > ORIGINAL ADVISORY: > MS06-038 (KB917284): > http://www.microsoft.com/technet/security/Bulletin/MS06-038.mspx >
Copyright © Lexa Software, 1996-2009.