Advisories Blog | G5 Cyber Security

iDEFENSE Security Advisory 2008-08-12.4

iDefense Security Advisory 08.12.08 – Remote exploitation of an integer overflow vulnerability in Microsoft Corp.’s PowerPoint Viewer 2003 could allow an attacker to execute arbitrary code in the context of the user running the application. This vulnerability specifically exists when handling CString objects embedded in a PowerPoint presentation file. An issue in this object results in a very small amount of buffer being allocated while a very large amount of data is copied into it. This leads to an exploitable heap-based buffer overflow. iDefense has confirmed that pptview.exe file version 11.0.5703.0 and file version 11.0.6566.0, as included in Microsoft Office 2003 SP2, are vulnerable. Other versions are also likely to be affected.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/69050/08.12.08-4.txt

Source: https://packetstormsecurity.com/files/69050/iDEFENSE-Security-Advisory-2008-08-12.4.html

Exit mobile version