SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#449438

Microsoft Office WordPerfect 5.x Converter contains a buffer overflow vulnerability

Overview

A buffer overflow vulnerability in the Microsoft Office WordPerfect 5.x Converter could allow a remote attacker to execute arbitrary code on a vulnerable system.

I. Description

The Microsoft Office WordPerfect 5.x Converter allows users to convert documents in WordPerfect format to Microsoft Word format. The way the converter validates the length of a parameter before passing it to its allocated buffer creates a buffer overflow vulnerability. By convincing a victim to open a specially crafted WordPerfect 5.x document using the WordPerfect 5.x Converter, a remote attacker could trigger a buffer overflow.

According to the Microsoft Security Bulletin, the following software is affected:

  • Microsoft Office 2000 Software Service Pack 3
  • Microsoft Office XP Software Service Pack 3
  • Microsoft Office 2003
  • Microsoft Works Suites

Microsoft notes that Office 2003 Service Pack 1 is not affected by this vulnerability.

II. Impact

By convincing a victim to open a specially crafted WordPerfect 5.x document, a remote attacker could execute arbitrary code with the privileges of the vulnerable process.

III. Solution

Apply Patch

Apply a patch as described in Microsoft Security Bulletin MS04-027.

Workarounds
According to the Microsoft Security Bulletin, the following workarounds are recommended:

    Do not open WordPerfect 5.x documents using the affected WordPerfect 5.x Converter.

    Do not open WordPerfect 5.x documents from untrusted sources using any software listed as affected in this bulletin on systems that are not updated with the security updates that accompany this bulletin.

    Uninstall the WordPerfect 5.x Converter.

    Uninstall the WordPerfect 5.x Converter from your system through Add or Remove Programs. Choose a program from the Affected Software list that is installed on your system and click Change. The WordPerfect 5.x Converter is an Office Shared Feature.

    Impact of workaround: Opening WordPerfect 5.x documents using any software listed in the Affected Software section would no longer be possible.

    Use a third-party WordPerfect 5.x to Word converter or ask the user of WordPerfect to save the document in another format.

Systems Affected

VendorStatusDate NotifiedDate Updated
Microsoft CorporationVulnerable15-Sep-2004

References


http://www.microsoft.com/technet/security/bulletin/MS04-027.mspx
http://secunia.com/advisories/12529/
http://www.securiteam.com/windowsntfocus/5RP0D1FE0A.html
http://www.securitytracker.com/alerts/2004/Sep/1011249.html
http://www.securitytracker.com/alerts/2004/Sep/1011250.html
http://www.securitytracker.com/alerts/2004/Sep/1011251.html
http://www.securitytracker.com/alerts/2004/Sep/1011252.html

Credit

This vulnerability was reported by Microsoft. Microsoft credits Peter Winter-Smith for discovering this vulnerability.

This document was written by Damon Morda based on information provided by Microsoft.

Other Information

Date Public:2004-09-14
Date First Published:2004-09-15
Date Last Updated:2004-09-17
CERT Advisory: 
CVE-ID(s):CAN-2004-0573
NVD-ID(s):CAN-2004-0573
US-CERT Technical Alerts: 
Metric:0.90
Document Revision:18

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2004 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader