Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2008-4025
StatusCandidate
DescriptionInteger overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via (1) an RTF file or (2) a rich text e-mail message containing an invalid number of points for a polyline or polygon, which triggers a heap-based buffer overflow, aka "Word RTF Object Parsing Vulnerability."
PhaseAssigned (10.09.2008)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4025
ReferencesBUGTRAQ : 20081209 Secunia Research: Microsoft Word RTF Polyline/Polygon Integer Overflow
 CERT : TA08-344A
 MISC : http://secunia.com/secunia_research/2008-21/
 MS : MS08-072
 OVAL : oval:org.mitre.oval:def:5682
 SECTRACK : 1021370
 VUPEN : ADV-2008-3384
SecurityVulns:Microsoft Office multiple security vulnerabilities

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server