|
|
| |
Credit:
The information has been provided by Carsten Eiram.
The original article can be found at: http://seclists.org/fulldisclosure/2010/Dec/523
|
| |
Vulnerable Systems:
* Microsoft Office XP SP3
* Microsoft Office Converter Pack
The vulnerability is caused by an error in the TIFF Import/Export Graphic Filter (TIFFIM32.FLT) when converting the endianess of certain data. This can be exploited to corrupt memory via e.g. a specially crafted TIFF image.
Successful exploitation may allow execution of arbitrary code when processing a TIFF image in an application using the graphics filter (e.g. opening the image in Microsoft Photo Editor or importing it into an Office document).
Patch Availability:
Apply patches provided by MS10-105:
http://www.microsoft.com/technet/security/bulletin/ms10-105.mspx
CVE Information:
CVE-2010-3949
Disclosure Timeline:
09/07/2009 - Vendor notified.
09/07/2009 - Vendor response.
08/11/2010 - Vendor informed that December is the final deadline.
14/12/2010 - Public disclosure.
|
|
|