Description: A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an integer overflow within HTML Help and can be exploited to cause a heap-based buffer overflow via a specially crafted Help (.chm) file with a very high value in a size field.
Successful exploitation allows execution of arbitrary code.
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, using the Network Software Inspector.
Provided and/or discovered by: The vulnerability was reported independently by:
* Peter Winter-Smith, Next Generation Security Software.
* Yuji Ukai, eEye Digital Security.
Changelog: 2005-06-15: Added links to advisories from eEye Digital Security, NGSSoftware and US-CERT vulnerability note.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.