|
|
| |
Credit:
The information has been provided by Carsten Eiram.
The original article can be found at: http://seclists.org/fulldisclosure/2010/Dec/524
|
| |
Vulnerable Systems:
* Microsoft Office XP SP3
* Microsoft Office Converter Pack
* Microsoft Works 9
The vulnerability is caused by missing input validation within a library used by the bundled Microsoft Office Document Imaging application when converting certain data during parsing of TIFF images. This can be exploited to corrupt memory via a TIFF image containing specially crafted IFD entries.
Successful exploitation may allow execution of arbitrary code.
Patch Availability:
Apply patches provided by MS10-105:
http://www.microsoft.com/technet/security/bulletin/ms10-105.mspx
CVE Information:
CVE-2010-3950
Disclosure Timeline:
09/07/2009 - Vendor notified.
09/07/2009 - Vendor response
08/11/2010 - Vendor informed that December is the final deadline.
14/12/2010 - Public disclosure.
|
|
|