Microsoft WordPad and Office Text Converters Multiple Vulnerabilities( 15 April 2009 )
RISK: Medium Risk
1. WordPad and Office Text Converter Memory Corruption Vulnerability
A remote code execution vulnerability exists in the way that text converters in WordPad and Microsoft Office process memory when a user opens a specially crafted Word 6 file that includes malformed data.
2. WordPad Word 97 Text Converter Stack Overflow Vulnerability
A remote code execution vulnerability exists in the way that Microsoft WordPad processes memory when parsing a specially crafted Word 97 document. The vulnerability could allow remote code execution if a user opens a specially crafted Word file that includes a malformed list structure.
3. Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability
A remote code execution vulnerability exists in the way that the WordPerfect 6.x converter that is included with Microsoft Office Word 2000 processes memory when parsing a specially crafted WordPerfect document.
4. WordPad Word 97 Text Converter Stack Overflow Vulnerability
A remote code execution vulnerability exists in WordPad as a result of memory corruption when a user opens a specially crafted Word file.
Impact
- Remote Code Execution
System / Technologies affected
- Microsoft Windows 2000
- Windows XP
- Windows Server 2003
- Microsoft Office 2000
- Microsoft Office Word 2000 - Microsoft Office XP
- Microsoft Office Word 2002 - Microsoft Office Converter Pack
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Download locations for this patch
- Microsoft Windows 2000 Service Pack 4
- Windows XP Service Pack 2 and Windows XP Service Pack 3
- Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2
- Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems
- Microsoft Office 2000 Service Pack 3
- - Microsoft Office Word 2000 Service Pack 3 - Microsoft Office XP Service Pack 3
- Microsoft Office Word 2002 Service Pack 3 - Microsoft Office Converter Pack
Vulnerability Identifier
Source
Related Link
Share with