|
Microsoft PowerPoint OutlineTextRefAtom Parsing Vulnerability
|
|
Secunia Advisory:
|
SA34572
|
|
|
Release Date:
|
2009-04-03
|
|
Last Update:
|
2009-06-10
|
|
Popularity:
|
22,291 views
|
|
|
Critical:
|
 Extremely critical
|
|
Impact:
|
System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Partial Fix
|
|
| Software: | Microsoft Office 2000 Microsoft Office 2003 Professional Edition Microsoft Office 2003 Small Business Edition Microsoft Office 2003 Standard Edition Microsoft Office 2003 Student and Teacher Edition Microsoft Office 2004 for Mac Microsoft Office XP Microsoft PowerPoint 2000 Microsoft PowerPoint 2002 Microsoft Powerpoint 2003
|
|
|
Binary Analysis:
|
BA707 :: Available for 1 Credit 
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 2 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Solution: Apply patches.
Microsoft Office PowerPoint 2000 SP3:
http://www.microsoft.com/downloads/de...=f443312a-ac74-4ebc-a4ac-7a756aa67894
Microsoft Office PowerPoint 2002 SP3:
http://www.microsoft.com/downloads/de...=a24ec7ab-c1c7-4ddb-8b6e-107f1af67f49
Microsoft Office PowerPoint 2003 SP3:
http://www.microsoft.com/downloads/de...=ccfa978b-3340-40db-a45d-c880ba36b106
Microsoft Office 2004 for Mac:
http://www.microsoft.com/downloads/de...=5557bfb7-ebb4-4c42-8042-41e830c4e550
Provided and/or discovered by: Reported as a 0-day.
Changelog: 2009-04-06: Added link to US-CERT.
2009-05-12: Updated "Solution" section. Added additional information provided by Microsoft.
2009-05-13: Added additional information provided by ZDI.
2009-06-10: Updated "Solution" section with patch information for "Microsoft Office 2004 for Mac". Updated "Original Advisory" section.
Original Advisory: MS09-017 (KB957781, KB957784, KB957789, KB957790, KB967340, KB969615, KB969618, KB970059, KB969661):
http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx
Microsoft:
http://www.microsoft.com/technet/security/advisory/969136.mspx
ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-09-019/
Other References: Microsoft:
http://blogs.technet.com/msrc/archive...crosoft-security-advisory-969136.aspx
http://blogs.technet.com/srd/archive/...igating-the-new-powerpoint-issue.aspx
http://blogs.technet.com/mmpc/archive...-exploits-using-powerpoint-files.aspx
US-CERT VU#627331:
http://www.kb.cert.org/vuls/id/627331
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|