bugtraq
[Top] [All Lists]

Few unreported vulnerabilities by SehaTo

To: bugtraq@securityfocus.com
Subject: Few unreported vulnerabilities by SehaTo
From: 3APA3A <3APA3A@security.nnov.ru>
Date: Sun, 25 Feb 2007 19:12:08 +0300
Cc: full-disclosure@lists.grok.org.uk
Delivered-to: sp-com-lists@consult.net
Delivered-to: bugtraq-list@securepoint.com
Delivered-to: mailing list bugtraq@securityfocus.com
Delivered-to: moderator for bugtraq@securityfocus.com
List-help: <mailto:bugtraq-help@securityfocus.com>
List-id: <bugtraq.list-id.securityfocus.com>
List-post: <mailto:bugtraq@securityfocus.com>
List-subscribe: <mailto:bugtraq-subscribe@securityfocus.com>
List-unsubscribe: <mailto:bugtraq-unsubscribe@securityfocus.com>
Mailing-list: contact bugtraq-help@securityfocus.com; run by ezmlm
Organization: www.security.nnov.ru
Reply-to: 3APA3A <3APA3A@security.nnov.ru>
Hello lists,

 SehaTo  (sehato at yandex ru) reported few vulnerabilities in different
 Windows  applications.  Original  messages (in Russian) may be found at
 http://securityvulns.com/source16446.html

 1. Microsoft Windows Explorer corrupted WMF vulnerability
 http://securityvulns.com/news/Microsoft/Windows/Explorer/DoS.html

 Windows   explorer  (explorer.exe)  crashes  on  browsing  folder  with
 corrupted WMF files.

 SecurityVulns  note:  from  the very fast debugging results analysis on
 Windows  XP  SP2, there is potential code execution possibility (memory
 corruption),  because  attacker-controllable  data  is used to contruct
 both  read  and write memory addresses. Deeper research of exploitation
 possibility was not performed.

 2. IfranView / Microsoft Office 2003 malformed WMF crash
 http://securityvulns.com/news/IrfanView/WMF/DoS.html

 IfranView  crashes  on  attempt to view malformed WMF, Microsoft Office
 crashes on attempt to insert corrupted WMF file.

 SecurityVulns note: because of relatively low impact, SecurityVulns did
 no research on this vulnerability.

 3. 2 different Microsoft Excel DoS conditions
 http://securityvulns.com/news/Microsoft/Excel/XML/DoS.html

 2 different crashes in Microsoft Excel on parsing .XLS files (corrupted
 XML and corrupted XLS formats).

 SecurityVulns  note: vulnerabilities confirmed on Microsoft Excel 2003.
 Both   vulnerabilities  are  of  NULL-pointer  dereference  type.  Code
 execution is probably impossible.

-- 
/3APA3A
http://securityvulns.com/


<Prev in Thread] Current Thread [Next in Thread>
  • Few unreported vulnerabilities by SehaTo, 3APA3A <=