Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:STC:DL:WORD-CONV-INT-OF

Severity

Major

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Microsoft WordPad and Office Text converter Integer Overflow

Release Date

2010/10/13

Update Number

1792

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Microsoft WordPad and Office Text converter Integer Overflow


his signature detects attempts to exploit a known integer overflow vulnerability in Microsoft WordPad and Office Text converter. It is due to lack of input validation while parsing specially crafted Word 97 documents. Remote attackers can exploit this by enticing a target user to open a malicious Word 97 document, potentially causing arbitrary code to be injected and executed in the security context of the current user. In a successful code injection attack, the behaviour of the target is dependent on the intention of the malicious code. In an unsuccessful attack, the application can terminate as a result of invalid memory access.

Extended Description

Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a DOC file with an invalid number of property names in the DocumentSummaryInformation stream, which triggers a heap-based buffer overflow.

Affected Products

  • Microsoft office_converter_pack *
  • Microsoft office_word 2002
  • Microsoft office_word 2003
  • Microsoft windows_2000 *
  • Microsoft windows_server_2003 *
  • Microsoft windows_xp *
  • Microsoft wordpad *
  • Microsoft works 8.5

References

  • BugTraq: 37216
  • CVE: CVE-2009-2506

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out