Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2009-0235
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2009-0235

Description:
Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an unspecified length field, aka "WordPad Word 97 Text Converter Stack Overflow Vulnerability."

CVE Status:
Candidate

References:

ST
  1022043

OSVDB
  53664

MS
  http://www.microsoft.com/technet/security/Bulletin/MS09-010.mspx

IDEFENSE
  http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=783

CERT
  http://www.us-cert.gov/cas/techalerts/TA09-104A.html

BID
  34470


Return to the previous page.