Secunia Logo
 
CVE Reference: CVE-2004-0572
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-0572

Description:
Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/16664
  http://xforce.iss.net/xforce/xfdb/17662

OVAL
  http://oval.mitre.org/oval/definitions/data/oval3822.html
  http://oval.mitre.org/oval/definitions/data/oval4244.html
  http://oval.mitre.org/oval/definitions/data/oval4493.html
  http://oval.mitre.org/oval/definitions/data/oval3768.html
  http://oval.mitre.org/oval/definitions/data/oval3071.html
  http://oval.mitre.org/oval/definitions/data/oval2753.html
  http://oval.mitre.org/oval/definitions/data/oval1843.html
  http://oval.mitre.org/oval/definitions/data/oval1837.html
  http://oval.mitre.org/oval/definitions/data/oval1279.html

MS
  http://www.microsoft.com/technet/security/bulletin/ms04-037.asp

FULLDISC
  http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0290.html

CERT-VN
  543864

BID
  10677


Return to the previous page.