Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-Disclosure] Finjan Security Advisory: Microsoft Office XP Remote Buffer Overflow Vulnerability |
|---|---|
| Date: | Wed, 9 Feb 2005 02:18:45 +0200 |
Finjan Security Advisory Microsoft Office XP Remote Buffer Overflow Vulnerability Introduction Finjan has discovered a new vulnerability in Microsoft Word XP that would allow a hacker to launch a buffer overflow attack. This attack could occur when a user opened a Word document using Internet Explorer. Technical Description When a ".doc" file is opened inside Internet Explorer, Microsoft Word XP "takes over" and opens that doc file. The problem appears when sending a doc file request that contains a null byte (parser) at the end of the doc filename (the rtf extension is also vulnerable). For example: http://www.myhost.com/myfile.doc is a valid request. However This: http://www.myhost.com/myfile.doc%00aaaaaaaaaaaaaaaaaaaaaaa...aa.doc is an invalid request. Such a request will be sent to the server hosting the doc file. Most servers like IIS and Apache will truncate the characters before the %00 while sending the filename to Internet Explorer. At this stage, Internet Explorer will hand over the string to Microsoft Word XP, which will now receive a long string. This string causes an exploitable buffer overflow, allowing remote code execution. The Code (Proof of Concept) <Script> var mylongstring,myjunk; mylongstring =""; myjunk="bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb bbbbbbbbbbbbbbbbbbb"; for(c=1;c<5000;c++) { mylongstring = mylongstring + myjunk; } window.open("http://www.hhs.gov/ocr/privacysummary.rtf%0a"+mylongstring); </script> Vulnerability Status Microsoft was notified on July 13, 2004. The bug is now fixed. For further details please refer to Microsoft security bulletin MS05-004. Credit Rafel Ivgi, Malicious Code Research Center (MCRC), Finjan Software Ltd. ----------------------------------------------- This message was scanned for malicious content and viruses by Finjan Internet Vital Security 1Box(tm) _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [VulnWatch] iDEFENSE Security Advisory 02.08.05: IBM AIX auditselect Local Format String Vulnerability, iDefense Customer Service |
|---|---|
| Next by Date: | [VulnWatch] GREENAPPLE Release, Dave Aitel |
| Previous by Thread: | [VulnWatch] iDEFENSE Security Advisory 02.08.05: IBM AIX auditselect Local Format String Vulnerability, iDefense Customer Service |
| Next by Thread: | [VulnWatch] GREENAPPLE Release, Dave Aitel |
| Indexes: | [Date] [Thread] [Top] [All Lists] |