Microsoft Office Buffer Overflow in Parsing Fonts Lets Remote Users Cause Arbitrary Code to Be Executed
|
|
SecurityTracker Alert ID: 1014458
|
|
SecurityTracker URL: http://securitytracker.com/id?1014458
|
|
CVE Reference: CAN-2005-0564
(Links to External Site)
|
Date: Jul 12 2005
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Microsoft Security Advisory
|
Version(s): Word 2000, Office 2000, Works 2001, Office XP, Word 2002, Works 2002, Works 2003, Works 2004 Word 2000 SP3, Office 2000 Service Pack 3, Works 2001 Gold, Office XP SP3, Word 2002 SP3, Works 2002 Gold, Works 2003 Gold, Works 2004 Gold
|
Description: A vulnerability was reported in Microsoft Office. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create a specially crafted document that, when processed by the target user, will trigger a buffer overflow and
execute arbitrary code on the target user's system. The code will run with the privileges of the target user.
The vulnerability
resides in the process used to process fonts.
Microsoft Office 2003 is not affected.
The vendor credits iDEFENSE with reporting
this vulnerability.
|
Impact: A remote user can create a document that, when opened by the target user, will execute arbitrary code on the target user's system with the privileges of the target user.
|
Solution: The vendor has issued the following fixes:
Microsoft Office 2000 Software Service Pack 3 (including Word 2000):
http://www.microsoft.com/downloads/details.aspx?Famil
yId=CEE0864B-B196-48F4-A4B9-2ED7FB6D17D2
Microsoft Office XP Software Service Pack 3 (including Word 2002):
http://www.microsoft.com/downloads/details.aspx?FamilyId
=A7E7D2C5-1E2A-4FFB-8FC2-B2B217015820
For Microsoft Works Suite 2000 and 2001:
http://www.microsoft.com/downloads/details.aspx?FamilyId=CEE0864B-B196-48F4-A4B9-2ED7
FB6D17D2
For Microsoft Works Suite 2002, 2003, and 2004:
http://www.microsoft.com/downloads/details.aspx?FamilyId=A7E7D2C5-1E2A-4FFB-8FC2-B2B217015820
A
restart may be required.
|
Vendor URL: www.microsoft.com/technet/security/Bulletin/MS05-035.mspx (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 12 Jul 2005 02:09:56 -0400
Subject: http://www.microsoft.com/technet/security/Bulletin/MS05-035.mspx
|
http://www.microsoft.com/technet/security/Bulletin/MS05-035.mspx
|
|