|
|
|
|
| |
Credit:
The information has been provided by Carsten Eiram.
The original article can be found at: http://secunia.com/secunia_research/2009-29/
|
| |
Vulnerable Systems:
* Microsoft Office PowerPoint 2000
* Microsoft Office PowerPoint 2002
Patch Availability:
Microsoft states that no fix will be issued. However, installations with MS09-017 applied block opening of Freelance files by default. Users having enabled Freelance file support should not open Freelance files from untrusted sources.
CVE Information:
CVE-2009-0202
Disclosure Timeline:
22/05/2009 - Vendor notified.
23/05/2009 - Vendor response.
03/06/2009 - Vendor informs that no security bulletin will be issued as Freelance files are blocked by default after applying MS09-017.
04/06/2009 - Vendor informed that Secunia agrees that a new security bulletin is not required. It is, however, recommended to update MS09-017 to inform users that Freelance support has been disabled by default and should not be re-enabled as the translator is affected by a critical vulnerability.
10/06/2009 - Public disclosure.
|
|
|
|
|