lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <15491864.62771150212463102.JavaMail.juha-matti.laurio@netti.fi> Date: Tue Jun 13 16:27:51 2006 From: juha-matti.laurio at netti.fi (Juha-Matti Laurio) Subject: Immunity: Word 0-day issue is problem in Smart Tags Microsoft will release a fix to code execution vulnerability in MS Word today ( http://www.microsoft.com/technet/security/advisory/919637.mspx CVE-2006-2492 etc.) Major sources say this vulnerability affecting Word 2003 and Word 2002 is problem in object handling. But it appears that one vendor (Immunity Inc.) had their non-public PoC in late May, already. After some hours we know more details about the vulnerability. Especially I'm interested what was the reason to recommend using Office Viewers as a workaround. Maybe these viewers don't support Smart Tags. MS has instruction to switch this feature off as well: http://office.microsoft.com/en-gb/assistance/HP030832781033.aspx I have written a detailed story to http://blogs.securiteam.com/index.php/archives/436 - Juha-Matti