Secunia - Stay Secure
Home Corporate Website Jobs Updated Mailing Lists RSS Blog  Online Shop Advertise
Software Inspectors
  Scan Online
  Personal (PSI)
  Network (NSI 2.0)

Solutions For
  Security Professionals
  Security Vendors

Free Solutions For
  Open Communities
  Journalists & Media

Secunia Advisories
  Search
  Historic Advisories
  Listed By Product
  Listed By Vendor
  Statistics / Graphs
  Secunia Research
  Report Vulnerability
  About Advisories

Virus Information
  Chronological List
  Last 10 Virus Alerts
  About Virus Information

Secunia Customers
  Customer Area


Microsoft Office flere kode-eksekveringssårbarheder Advisory Available in English 

Secunia Advisory: SA22339  
Udsendt: 2006-10-10
Sidste Opdt.: 2006-10-12

Kritisk:
Meget kritisk
Betydning: Systemadgang
Hvor: Fra Internet
Løsning Status: Producent Patch

Software:Microsoft Access 2000
Microsoft Access 2002
Microsoft Access 2003
Microsoft Excel 2000
Microsoft Excel 2002
Microsoft Excel 2003
Microsoft Excel Viewer 2003
Microsoft Frontpage 2000
Microsoft Frontpage 2002
Microsoft Frontpage 2003
Microsoft InfoPath 2003
Microsoft Office 2000
Microsoft Office 2003 Professional Edition
Microsoft Office 2003 Small Business Edition
Microsoft Office 2003 Standard Edition
Microsoft Office 2003 Student and Teacher Edition
Microsoft Office 2004 for Mac
Microsoft Office X for Mac
Microsoft Office XP
Microsoft OneNote 2003
Microsoft Outlook 2000
Microsoft Outlook 2002
Microsoft Outlook 2003
Microsoft PowerPoint 2000
Microsoft PowerPoint 2002
Microsoft Powerpoint 2003
Microsoft Project 2000
Microsoft Project 2002
Microsoft Project 2003
Microsoft Publisher 2000
Microsoft Publisher 2002
Microsoft Publisher 2003
Microsoft Visio 2002
Microsoft Visio 2003
Microsoft Word 2000
Microsoft Word 2002
Microsoft Word 2003
Microsoft Word Viewer 2003

CVE reference:CVE-2006-3434 (Secunia mirror)
CVE-2006-3650 (Secunia mirror)
CVE-2006-3864 (Secunia mirror)
CVE-2006-3868 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Beskrivelse:
Der er rapporteret flere sårbarheder i Microsoft Office, som kan udnyttes af ondsindede personer til at kompromittere en brugers system.

1) En uspecificeret ikke-kontrolleret buffer under fortolkningen af visse strenge kan udnyttes til at forårsage et buffer overflow via et specielt udformet Office-dokument.

2) En ikke-kontrolleret buffer under fortolkningen af chart-records kan udnyttes til at forårsage et buffer overflow via et specielt udformet Office-dokument.

3) En uspecificeret ikke-kontrolleret buffer under fortolkningen af visse records kan udnyttes til at forårsage et buffer overflow via et specielt udformet Office-dokument.

4) En ikke-kontrolleret buffer under fortolkningen af Smart Tags kan udnyttes til at forårsage et buffer overflow via et specielt udformet Office-dokument.

Succesfuld udnyttelse af sårbarhederne muliggør eksekvering af vilkårlig kode.

Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, scan using the Network Software Inspector.

Løsning:
Installér patches.

Microsoft Office 2000 SP3:
http://www.microsoft.com/downloads/de...=E0C7E1E4-7859-4C7E-898E-1CF05014885B

Microsoft Office XP SP3:
http://www.microsoft.com/downloads/de...=958EE063-D88D-4E45-8555-4D1C4730F5C8

Microsoft Office 2003 SP1/SP2:
http://www.microsoft.com/downloads/de...=0D399F68-EC0D-4768-9846-B16B3DADF247

Microsoft Project 2000 SR1:
http://www.microsoft.com/downloads/de...=266A9870-CD03-45CA-877B-B5AD2C873FE5

Microsoft Project 2002 SP1:
http://www.microsoft.com/downloads/de...=A77DEA18-D237-4BB0-9464-CE31B6AE52D6

Microsoft Visio 2002 SP2:
http://www.microsoft.com/downloads/de...=FD4B7660-0FC5-43E5-9683-B6DAE96136BB

Microsoft Office 2004 for Mac:
http://www.microsoft.com/mac/

Microsoft Office v. X for Mac:
http://www.microsoft.com/mac/

Rapporteret af / Kredit:
1) Dejun Meng, Fortinet Security Research Team.
2) Arnaud Dovi.
3) Sowhat, Nevis Labs.

Forløb:
11-10-2006: Tilføjede links til Fortinet, ZDI og Sowhat. Tilføjede links til US-CERT.
12-10-2006: Tilføjede link til US-CERT.

Original Advisory:
MS06-062 (KB922581):
http://www.microsoft.com/technet/security/Bulletin/MS06-062.mspx

Fortinet:
http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-27.html

Sowhat:
http://secway.org/advisory/AD20061010.txt

ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-06-034.html

Andre Kilder:
US-CERT VU#534276:
http://www.kb.cert.org/vuls/id/534276

US-CERT VU#234900:
http://www.kb.cert.org/vuls/id/234900

US-CERT VU#176556:
http://www.kb.cert.org/vuls/id/176556

US-CERT VU#807780:
http://www.kb.cert.org/vuls/id/807780



Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.

73 Relaterede Secunia Advisories, displaying 10

1. Microsoft Excel kode eksekvering
2. Microsoft Word uspecificeret hukommelses-korrumpering
3. Microsoft Windows OLE Automation hukommelses-korrumpering
4. Microsoft XML Core Services "substringData()" heltals-overflow
5. Microsoft Excel rtWnDesk record hukommelses-korrumpering
6. Microsoft Excel flere kode-eksekveringssårbarheder
7. Microsoft Visio eksekvering af vilkårlige kode
8. Microsoft Office drawing-objekt kode-eksekvering
9. Microsoft Excel tre kode-eksekveringssårbarheder
10. Microsoft RichEdit OLE-dialog hukommelses-korrumpering

Vis alle relaterede advisories


Send Feedback to Secunia

Hvis du har ny information angående dette Secunia advisory eller et produkt i vores database, så send det venligst til os. Du kan sende det til os enten ved at bruge vores web formular eller ved at sende det til vuln@secunia.com.

Ideer, foreslag og andet feedback er også meget velkommen.








Secunia PSI
Scan | Patch | Track
Free Download

Secunia Poll

Do you think it's important to read Setup/User Guides for applications for use within your network?


See Results   


Most Popular Advisories

1.
Opera Multiple Vulnerabilities
2.
Sun Solaris NFSv4 Client Kernel Module Denial of Service
3.
Subdreamer Light Global Variables SQL Injection Vulnerability
4.
Banner Management "id" SQL Injection Vulnerability
5.
Avaya CMS Solaris "picld" Denial of Service
6.
Active PHP Bookmarks "id" SQL Injection Vulnerability
7.
Avaya CMS Solaris "snoop" Multiple Vulnerabilities
8.
Ubuntu update for postfix
9.
Avaya CMS Solaris namefs Kernel Module Privilege Escalation
10.
WS_FTP Home / Professional Format String Vulnerability





Vulnerability Management - Terms & Conditions - Copyright 2002-2008 Secunia - Compliance - Contact Secunia