All Threats

Viruses

Hackers

Spam

Whole site    Viruses
  
About Hackers
Analysis
News
Glossary
Weblog



 
Virus Encyclopedia
Virus Encyclopedia

Learn about worms, viruses, Trojans and more in our Virus Encyclopedia.

About Spam
About Spam

Read about spam and spammers in our About Spam section.

 

  Home / Hackers / About Hackers / Software Vulnerabilities / Examples and Descriptions / SA30143

Microsoft Word Two Code Execution Vulnerabilities

Secunia ID

SA30143

CVE-ID

CVE-2008-1091, CVE-2008-1434

Release Date

13 May 2008

Last Change

14 May 2008

Solution Status

Vendor Patch

Software

Microsoft Office 2000
Microsoft Office 2003 Professional Edition
Microsoft Office 2003 Small Business Edition
Microsoft Office 2003 Standard Edition
Microsoft Office 2003 Student and Teacher Edition
Microsoft Office 2004 for Mac
Microsoft Office 2007
Microsoft Office 2008 for Mac
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
Microsoft Office Word 2007
Microsoft Office XP
Microsoft Word 2000
Microsoft Word 2002
Microsoft Word 2003
Microsoft Word Viewer 2003

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.


Description

Two vulnerabilities have been reported in Microsoft Word, which can be exploited by malicious people to compromise a user's system.

1) An error when parsing objects in rich text format (.rtf) files can be exploited to cause a heap-based buffer overflow e.g. when a user opens a specially crafted .rtf file containing malformed strings with Word or previews a specially crafted e-mail containing malformed strings as rich text or HTML.

2) An error exists in the processing of cascading style sheets (CSS) values and can be exploited to corrupt memory when a specially crafted HTML file is opened using Word.

Successful exploitation may allow execution of arbitrary code.

Solution

Apply updates.

Microsoft Office 2000 SP3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=9215ff71-38c0-416a-b89a-fe3474160f41

Microsoft Office XP SP3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=b348a518-221e-4567-a797-999715a8b2ef

Microsoft Office 2003 SP2/SP3:
http://www.microsoft.com/downloads/details.aspx?FamilyId=bc33d144-f917-47b8-961f-744ca847e14c

2007 Microsoft Office System (optionally with SP1):
http://www.microsoft.com/downloads/details.aspx?FamilyId=071ceaa2-12e3-4401-9331-2a54a93e2550

Microsoft Word Viewer 2003 (optionally with SP3):
http://www.microsoft.com/downloads/details.aspx?FamilyId=bce7ea31-2bf0-4930-aff9-837bcc82a682
x?FamilyId=bce7ea31-2bf0-4930-aff9-837bcc82a682

Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats (optionally with SP1):
http://www.microsoft.com/downloads/details.aspx?FamilyId=2d718f37-c5d1-4e15-a7e1-5a15fedef52f

Microsoft Office 2004 for Mac:
http://www.microsoft.com/downloads/details.aspx?FamilyId=99F54471-CCF9-4D94-A882-A05ECD128ADC

Microsoft Office 2008 for Mac:
http://www.microsoft.com/downloads/details.aspx?FamilyId=395D1487-A3A6-4106-A0F8-4D6E1D6D89D2

Reported by

1) wushi, team509 via Zero Day Initiative (ZDI).
2) Jun Mao, iDefense Labs.

Original Advisory

MS08-026:
http://www.microsoft.com/technet/security/bulletin/ms08-026.mspx

iDefense Labs:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=700

ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-08-023/




 

Copyright © 1996 - 2008
Kaspersky Lab
Industry-leading Antivirus Software
All rights reserved
 

Email: webmaster@viruslist.com