Get a Pentest and security assessment of your IT network.

Advisories

Zero Day Initiative Advisory 09-035

Zero Day Initiative Advisory 09-035 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page, open a malicious e-mail, or open a malicious file. The specific flaw exists within the parsing of vulnerable tags inside a Microsoft Word document. Microsoft Word trusts a length field read from the file which is used to read file contents into a buffer allocated on the stack. When an invalid length is present, a stack based buffer overflow occurs, resulting in the ability to execute arbitrary code.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/78239/ZDI-09-035.txt

Source: https://packetstormsecurity.com/files/78239/Zero-Day-Initiative-Advisory-09-035.html

Related posts
Advisories

Secunia Security Advisory 32959

Advisories

Secunia Security Advisory 35923

Advisories

Secunia Security Advisory 38902

Advisories

Ubuntu Security Notice 93-1