what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

CT12-09-2006-2.txt

CT12-09-2006-2.txt
Posted Sep 13, 2006
Authored by Stuart Pearson | Site computerterrorism.com

Microsoft Publisher versions 2000, 2002, and 2003 suffer from a remote, arbitrary code execution vulnerability that yields full system access running in the context of a target user.

tags | advisory, remote, arbitrary, code execution
advisories | CVE-2006-0001
SHA-256 | b11478ca1b4f1ca6846df7f7f3ed6ee5ff4d59deabf85210e4d91b95bb0635c0

CT12-09-2006-2.txt

Change Mirror Download
Computer Terrorism  (UK) :: Incident Response Centre

www.computerterrorism.com

Security Advisory: CT12-09-2006-2.htm


==============================================
Microsoft Publisher Font Parsing Vulnerability
==============================================

Advisory Date: 12th, September 2006

Severity: Critical
Impact: Remote System Access
Solution Status: Vendor Patch

CVE Reference: CVE-2006-0001


Affected Software
=================

Microsoft Publisher 2000 (Office 2000)
Microsoft Publisher 2002 (Office 2002)
Microsoft Publisher 2003 (Office 2003)



1. OVERVIEW
===========

Microsoft Publisher is a lightweight desktop publishing (DTP) application
bundled with Microsoft Office Small Business and Professional. The
application facilitates the design of professional business and marketing
communications via familiar Office tools & functionality.

Unfortunately, it transpires that Microsoft Publisher is susceptible to a
remote, arbitrary code execution vulnerability that yields full system
access running in the context of a target user.



2. TECHNICAL NARRATIVE
======================

The vulnerability emanates from Publishers inability to perform sufficient
data validation when processing the contents of a .pub document. As a
result, it is
possible to modify a .pub file in such a way that when opened will corrupt
critical system memory, allowing an attacker to execute code of his choice.

More specifically, the vulnerable condition is derived from an attacker
controlled string that facilitates an "extended" memory overwrite using
portions of the original
.pub file.

As no checks are made on the length of the data being copied, the net result
is that of a classic "stack overflow" condition, in which EIP control is
gained via one of several return addresses.


3. EXPLOITATION
===============

As with most file orientated vulnerabilities, the aforementioned issue
requires a certain degree of social engineering to achieve successful
exploitation.

However, users of Microsoft Publisher 2000 (Office 2000) are at an increased
risk due to the exploitability of the vulnerability in a possible web-based
attack scenario.



4. VENDOR RESPONSE
==================

The vendor security bulletin and corresponding patches are available at the
following location:

http://www.microsoft.com/technet/security/Bulletin/MS06-054.mspx


5. DISCLOSURE ANALYSIS
======================

03/08/2005 Preliminary Vendor notification.
12/08/2005 Vulnerability confirmed by Vendor.
03/01/2006 Public Disclosure Deferred by Vendor.
11/07/2006 Public Disclosure Deferred by Vendor.
12/09/2006 Coordinated public release.

Total Time to Fix: 1 year, 1 month, 6 days (402 days)


6. CREDIT
=========

The vulnerability was discovered by Stuart Pearson of Computer Terrorism

========================
About Computer Terrorism
========================

Computer Terrorism (UK) Ltd is a global provider of Digital Risk
Intelligence services. Our unique approach to vulnerability risk assessment
and mitigation has helped protect some of the worlds most at risk
organisations.

Headquartered in London, Computer Terrorism has representation throughout
Europe & North America and can be reached at +44 (0) 870 250 9866 or email:-

sales [at] computerterrorism.com

To learn more about our services and to register for a FREE comprehensive
website penetration test, visit: http:/www.computerterrorism.com


Computer Terrorism (UK) :: Protection for a vulnerable world.



Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close