|
|
| |
Credit:
The information has been provided by Dyon Balding.
The original article can be found at: http://seclists.org/fulldisclosure/2010/Dec/536
|
| |
Vulnerable Systems:
* Microsoft Office XP SP3
* Microsoft Office Converter Pack
1) A boundary error in the FlashPix graphics filter when parsing certain tile data can be exploited to cause a data section buffer overflow via a specially crafted image.
2) A boundary error in the FlashPix graphics filter when parsing certain tile data can be exploited to cause a stack-based buffer overflow via a specially crafted image.
Successful exploitation of the vulnerabilities allows execution of arbitrary code.
Patch Availability:
Apply patches provided by MS10-105:
http://www.microsoft.com/technet/security/bulletin/ms10-105.mspx
CVE Information:
CVE-2010-3952
Disclosure Timeline:
27/07/2009 - Vendor notified.
27/07/2009 - Vendor response.
08/11/2010 - Vendor informed that this is the final deadline.
14/12/2010 - Public disclosure.
|
|
|