CVE-2009-0088 Information
Description
The WordPerfect 6.x Converter (WPFT632.CNV 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file related to an unspecified counter and control structures on the stack aka \Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability.\
Reference
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=782 http://osvdb.org/53663 http://www.securitytracker.com/id?1022043 http://www.us-cert.gov/cas/techalerts/TA09-104A.html http://www.vupen.com/english/advisories/2009/1024 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-010 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A5736
Share on: