|
Microsoft Word Two Code Execution Vulnerabilities
|
|
Secunia Advisory:
|
SA30143
|
|
|
Release Date:
|
2008-05-13
|
|
Last Update:
|
2008-05-14
|
|
Popularity:
|
7,427 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Microsoft Office 2000 Microsoft Office 2003 Professional Edition Microsoft Office 2003 Small Business Edition Microsoft Office 2003 Standard Edition Microsoft Office 2003 Student and Teacher Edition Microsoft Office 2004 for Mac Microsoft Office 2007 Microsoft Office 2008 for Mac Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Microsoft Office Word 2007 Microsoft Office XP Microsoft Word 2000 Microsoft Word 2002 Microsoft Word 2003 Microsoft Word Viewer 2003
|
|
|
Binary Analysis:
|
BA474 :: Available for Credits  BA475 :: Available for 1 Credit 
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2008-1091 CVE-2008-1434
|
|
Description: Two vulnerabilities have been reported in Microsoft Word, which can be exploited by malicious people to compromise a user's system.
1) An error when parsing objects in rich text format (.rtf) files can be exploited to cause a heap-based buffer overflow e.g. when a user opens a specially crafted .rtf file containing malformed strings with Word or previews a specially crafted e-mail containing malformed strings as rich text or HTML.
2) An error exists in the processing of cascading style sheets (CSS) values and can be exploited to corrupt memory when a specially crafted HTML file is opened using Word.
Successful exploitation may allow execution of arbitrary code.
Solution: Apply updates.
Microsoft Office 2000 SP3:
http://www.microsoft.com/downloads/de...=9215ff71-38c0-416a-b89a-fe3474160f41
Microsoft Office XP SP3:
http://www.microsoft.com/downloads/de...=b348a518-221e-4567-a797-999715a8b2ef
Microsoft Office 2003 SP2/SP3:
http://www.microsoft.com/downloads/de...=bc33d144-f917-47b8-961f-744ca847e14c
2007 Microsoft Office System (optionally with SP1):
http://www.microsoft.com/downloads/de...=071ceaa2-12e3-4401-9331-2a54a93e2550
Microsoft Word Viewer 2003 (optionally with SP3):
http://www.microsoft.com/downloads/de...=bce7ea31-2bf0-4930-aff9-837bcc82a682
x?FamilyId=bce7ea31-2bf0-4930-aff9-837bcc82a682
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats (optionally with SP1):
http://www.microsoft.com/downloads/de...=2d718f37-c5d1-4e15-a7e1-5a15fedef52f
Microsoft Office 2004 for Mac:
http://www.microsoft.com/downloads/de...=99F54471-CCF9-4D94-A882-A05ECD128ADC
Microsoft Office 2008 for Mac:
http://www.microsoft.com/downloads/de...=395D1487-A3A6-4106-A0F8-4D6E1D6D89D2
Provided and/or discovered by: 1) wushi, team509 via Zero Day Initiative (ZDI).
2) Jun Mao, iDefense Labs.
Changelog: 2008-05-14: Updated "Description" section based on additional information from iDefense Labs and ZDI. Added links to iDefense Labs, ZDI, and US-CERT.
Original Advisory: MS08-026:
http://www.microsoft.com/technet/security/bulletin/ms08-026.mspx
iDefense Labs:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=700
ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-08-023/
Other References: US-CERT VU#543907:
http://www.kb.cert.org/vuls/id/543907
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|