|
|
| |
| The vulnerability is caused due to an integer overflow error when processing the number of strings in a file and can be exploited to cause a heap-based buffer overflow via a specially crafted Excel file. Successful exploitation allows execution of arbitrary code. |
| |
Credit:
The information has been provided by Carsten Eiram.
The original article can be found at: http://secunia.com/secunia_research/2009-12/
|
| |
Vulnerable Systems:
* Microsoft Office Excel 2003
Patch Availability:
http://www.microsoft.com/technet/security/Bulletin/MS09-021.mspx
CVE Information:
CVE-2009-056
Disclosure Timeline:
10/03/2009 - Vendor notified.
10/03/2009 - Vendor response.
19/05/2009 - Status update requested.
22/05/2009 - Vendor provides status update.
09/06/2009 - Public disclosure.
|
|
|