Description: Some vulnerabilities have been reported in Microsoft Excel, which can be exploited by malicious people to compromise a user's system.
1) A boundary error within the parsing of DATETIME records can be exploited to cause a buffer overflow via a specially crafted spreadsheet.
2) A boundary error within the parsing of STYLE records can be exploited to cause a buffer overflow via a specially crafted spreadsheet.
3) A boundary error when parsing Lotus 1-2-3 files can be exploited to cause a buffer overflow via a specially crafted file.
4) A boundary error within the parsing of COLINFO records can be exploited to cause a buffer overflow via a specially crafted spreadsheet.
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.
Provided and/or discovered by: 1) Manuel Santamarina Suarez.
2) Nanika
4) The vendor credits NSFocus Security Team.
Changelog: 2006-07-11: Added CVE reference.
2006-10-10: Added additional information provided by Microsoft.
2006-10-11: Added additional information provided by ZDI. Added links to US-CERT.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.