|
|
|
Microsoft Office Word Multiple Vulnerabilities
|
|
Secunia Advisory:
|
SA30285
|
|
|
Release Date:
|
2008-12-09
|
|
Last Update:
|
2009-01-14
|
|
Popularity:
|
15,059 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Microsoft Office 2000 Microsoft Office 2003 Professional Edition Microsoft Office 2003 Small Business Edition Microsoft Office 2003 Standard Edition Microsoft Office 2003 Student and Teacher Edition Microsoft Office 2004 for Mac Microsoft Office 2007 Microsoft Office 2008 for Mac Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Microsoft Office Word 2007 Microsoft Office Word Viewer Microsoft Office XP Microsoft Open XML File Format Converter for Mac Microsoft Outlook 2007 Microsoft Word 2000 Microsoft Word 2002 Microsoft Word 2003 Microsoft Word Viewer 2003 Microsoft Works 8.x
|
|
|
Binary Analysis:
|
BA479 :: Available for 1 Credit  BA627 :: Available for 1 Credit  BA638 :: Available for 1 Credit  BA636 :: Available for 1 Credit  BA634 :: Available for 1 Credit 
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 2 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Solution: Apply patches.
Microsoft Office Word 2000 SP3:
http://www.microsoft.com/downloads/de...=43e8c4d8-307b-48f6-ac99-a9617421d40a
Microsoft Office Word 2002 SP3:
http://www.microsoft.com/downloads/de...=3ef41412-50b3-4077-b0e3-9a3704d2f876
Microsoft Office Word 2003 SP3:
http://www.microsoft.com/downloads/de...=45c81c60-4b1b-4246-839b-198ebc4eeae2
Microsoft Office Word 2007:
http://www.microsoft.com/downloads/de...=5b51cb5e-3899-4257-82cf-7e92fa619c37
Microsoft Office Outlook 2007:
http://www.microsoft.com/downloads/de...=5b51cb5e-3899-4257-82cf-7e92fa619c37
Microsoft Office Word 2007 SP1:
http://www.microsoft.com/downloads/de...=5b51cb5e-3899-4257-82cf-7e92fa619c37
Microsoft Office Outlook 2007 SP1:
http://www.microsoft.com/downloads/de...=5b51cb5e-3899-4257-82cf-7e92fa619c37
Microsoft Office Word Viewer 2003:
http://www.microsoft.com/downloads/de...=70de7c3c-519f-4f4a-a03f-027f80b5415c
Microsoft Office Word Viewer 2003 SP3:
http://www.microsoft.com/downloads/de...=70de7c3c-519f-4f4a-a03f-027f80b5415c
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats:
http://www.microsoft.com/downloads/de...=55430121-4476-48b8-9f6f-4a60fa0b2970
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1:
http://www.microsoft.com/downloads/de...=55430121-4476-48b8-9f6f-4a60fa0b2970
Microsoft Works 8 (requires update to Works 8.5):
http://www.microsoft.com/downloads/de...=1537d181-90d9-4bb5-b5ae-8d9990a349af
Microsoft Office 2004 for Mac:
http://www.microsoft.com/downloads/de...=ECA13AD8-62AE-41A8-B308-41E2D1773820
Microsoft Office 2008 for Mac:
http://www.microsoft.com/downloads/de...=AB31A564-43D2-45BD-98BF-19E9CA477B62
Open XML File Format Converter for Mac:
http://www.microsoft.com/downloads/de...=EDB6CD8F-832C-4123-8982-AC0C601EA0A7
Microsoft Office Word Viewer:
http://www.microsoft.com/downloads/de...=70de7c3c-519f-4f4a-a03f-027f80b5415c
Provided and/or discovered by: 1) The vendor credits Ricardo Narvaja, Core Security Technologies.
2) Dyon Balding, Secunia Research.
3) The vendor credits Yamata Li, Palo Alto Networks.
4) The vendor credits Wushi via ZDI.
5) The vendor credits Aaron Portnoy, TippingPoint DVLabs.
6) The vendor credits Wushi of team509 via ZDI.
7) The vendor credits Aaron Portnoy, TippingPoint DVLabs.
8) The vendor credits Wushi and Ling via ZDI.
Changelog: 2008-12-10: Added additional details for vulnerabilities #4-#8. Added reporter links to the "Original Advisory" section.
2008-12-11: Added additional information to vulnerability #1. Added link in "Original Advisory" section.
2008-12-17: Updated description for vulnerability #1 based on information from Secunia Research.
2009-01-14: Added "Microsoft Office Word Viewer" to the list of affected products. Updated "Solution" section with link to "Microsoft Office Word Viewer" patch.
Original Advisory: MS08-072 (KB957173):
http://www.microsoft.com/technet/security/Bulletin/MS08-072.mspx
Secunia Research:
http://secunia.com/secunia_research/2008-21/
ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-08-084/
http://www.zerodayinitiative.com/advisories/ZDI-08-085/
http://www.zerodayinitiative.com/advisories/ZDI-08-086/
TippingPoint DVLabs:
http://dvlabs.tippingpoint.com/advisory/TPTI-08-08
http://dvlabs.tippingpoint.com/advisory/TPTI-08-09
Core Security Technologies:
http://www.coresecurity.com/content/word-arbitrary-free
Extended Solution: The "Extended Solution" section is available for Secunia customers only. Request a trial and get access to the Secunia Customer Area and Extended Secunia advisories.
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
Today
|
New advisories:
|
5 |
|
New vulnerabilities:
|
65 |
|
Updated advisories:
|
16 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
9th Nov, 2009
|
New advisories:
|
6 |
|
New vulnerabilities:
|
23 |
|
Updated advisories:
|
65 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Solutions | More...
|
|
|
|
Send Feedback to Secunia
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|
|
|
|