Microsoft Word ' FIB' Value Heap Memory Corruption Vulnerability
BID:32580
Info
Microsoft Word ' FIB' Value Heap Memory Corruption Vulnerability
| Bugtraq ID: | 32580 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-4024 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2008 12:00AM |
| Updated: | Jan 13 2009 07:02PM |
| Credit: | Ricardo Narvaja of Core Security Technologies |
| Vulnerable: |
Microsoft Word 2002 SP3 Microsoft Word 2000 SP3 Microsoft Office Word Viewer 0 Microsoft Office 2004 for Mac 0 |
| Not Vulnerable: | |
Discussion
Microsoft Word ' FIB' Value Heap Memory Corruption Vulnerability
Microsoft Word is prone to a heap-based memory-corruption vulnerability.
An attacker can exploit this issue by sending a specially crafted Word file to an unsuspecting user and enticing them to open it with a vulnerable application. A successful exploit will allow attackers to execute arbitrary code within the context of the user running the affected application.
Microsoft Word is prone to a heap-based memory-corruption vulnerability.
An attacker can exploit this issue by sending a specially crafted Word file to an unsuspecting user and enticing them to open it with a vulnerable application. A successful exploit will allow attackers to execute arbitrary code within the context of the user running the affected application.
Exploit / POC
Microsoft Word ' FIB' Value Heap Memory Corruption Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Word ' FIB' Value Heap Memory Corruption Vulnerability
Solution:
The vendor has released an advisory and updates to address this issue. Please see the referenced advisory for details.
Microsoft Word 2002 SP3
Microsoft Office 2004 for Mac 0
Microsoft Word 2000 SP3
Solution:
The vendor has released an advisory and updates to address this issue. Please see the referenced advisory for details.
Microsoft Word 2002 SP3
-
Microsoft Security Update for Microsoft Word 2002 (KB956329)
http://www.microsoft.com/downloads/details.aspx?FamilyId=3ef41412-50b3 -4077-b0e3-9a3704d2f876
Microsoft Office 2004 for Mac 0
-
Microsoft Microsoft Office 2004 for Mac 11.5.3 Update
http://www.microsoft.com/downloads/details.aspx?FamilyId=ECA13AD8-62AE -41A8-B308-41E2D1773820
Microsoft Word 2000 SP3
-
Microsoft Security Update for Microsoft Word 2000 (KB956328)
http://www.microsoft.com/downloads/details.aspx?FamilyId=43e8c4d8-307b -48f6-ac99-a9617421d40a
References
Microsoft Word ' FIB' Value Heap Memory Corruption Vulnerability
References:
References:
- Microsoft Office Product Homepage (Microsoft)
- CORE-2008-0228: Microsoft Word Malformed FIB Arbitrary Free Vulnerability (CORE Security Technologies Advisories
) - Microsoft Security Bulletin MS08-072 (Microsoft)
- Microsoft Word Malformed FIB Arbitrary Free Vulnerability (CORE Security Technologies Advisories)