Thread-topic: [SA21061] Microsoft PowerPoint Memory Corruption Vulnerability
>
> TITLE:
> Microsoft PowerPoint Memory Corruption Vulnerability
>
> SECUNIA ADVISORY ID:
> SA21061
>
> VERIFY ADVISORY:
>
>
> CRITICAL:
> Highly critical
>
> IMPACT:
> DoS, System access
>
> WHERE:
> From remote
>
> SOFTWARE:
> Microsoft Office 2000
>
> Microsoft Office 2003 Professional Edition
>
> Microsoft Office 2003 Small Business Edition
>
> Microsoft Office 2003 Standard Edition
>
> Microsoft Office 2003 Student and Teacher Edition
>
> Microsoft Office PowerPoint 2003 Viewer
>
> Microsoft Office XP
>
> Microsoft PowerPoint 2000
>
> Microsoft PowerPoint 2002
>
> Microsoft Powerpoint 2003
>
>
> DESCRIPTION:
> naveed has discovered a vulnerability in Microsoft PowerPoint, which
> potentially can be exploited by malicious people to compromise a
> user's system.
>
> The vulnerability is caused due to the application using data taken
> directly from a PowerPoint presentation file as a pointer when saving
> or closing the presentation. This can be exploited to corrupt memory
> and manipulate the program flow in various ways.
>
> Successful exploitation crashes the application and arbitrary code
> execution may potentially also be possible, but has not currently
> been proven.
>
> The vulnerability has been confirmed on Windows XP SP2 with a fully
> patched PowerPoint 2003. Other versions may also be affected.
>
> NOTE: Two other issues, which can be exploited to crash the
> application, have also been reported.
>
> SOLUTION:
> Do not open untrusted Office documents.
>
> PROVIDED AND/OR DISCOVERED BY:
> naveed
>