|
|
|
![]() |
Vulnerability Note VU#449438Microsoft Office WordPerfect 5.x Converter contains a buffer overflow vulnerabilityOverviewA buffer overflow vulnerability in the Microsoft Office WordPerfect 5.x Converter could allow a remote attacker to execute arbitrary code on a vulnerable system.I. DescriptionThe Microsoft Office WordPerfect 5.x Converter allows users to convert documents in WordPerfect format to Microsoft Word format. The way the converter validates the length of a parameter before passing it to its allocated buffer creates a buffer overflow vulnerability. By convincing a victim to open a specially crafted WordPerfect 5.x document using the WordPerfect 5.x Converter, a remote attacker could trigger a buffer overflow.According to the Microsoft Security Bulletin, the following software is affected:
Microsoft notes that Office 2003 Service Pack 1 is not affected by this vulnerability. II. ImpactBy convincing a victim to open a specially crafted WordPerfect 5.x document, a remote attacker could execute arbitrary code with the privileges of the vulnerable process.III. SolutionApply PatchApply a patch as described in Microsoft Security Bulletin MS04-027.
Do not open WordPerfect 5.x documents from untrusted sources using any software listed as affected in this bulletin on systems that are not updated with the security updates that accompany this bulletin. Uninstall the WordPerfect 5.x Converter. Uninstall the WordPerfect 5.x Converter from your system through Add or Remove Programs. Choose a program from the Affected Software list that is installed on your system and click Change. The WordPerfect 5.x Converter is an Office Shared Feature. Impact of workaround: Opening WordPerfect 5.x documents using any software listed in the Affected Software section would no longer be possible. Use a third-party WordPerfect 5.x to Word converter or ask the user of WordPerfect to save the document in another format. Systems Affected
References
This vulnerability was reported by Microsoft. Microsoft credits Peter Winter-Smith for discovering this vulnerability. This document was written by Damon Morda based on information provided by Microsoft.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||