Description
Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.
Affected products
- Microsoft / office
- Microsoft / officexp – xp
- Microsoft / officexp – xp
- Microsoft / officexp – xp
- Microsoft / PowerPoint2002 – 2002
- Microsoft / PowerPoint2002 – 2002
- Microsoft / PowerPoint2002 – 2002
- Microsoft / PowerPoint2002 – 2002
- Microsoft / project2002 – 2002
- Microsoft / project2002 – 2002
- Microsoft / visio2002 – 2002
- Microsoft / visio2002 – 2002
- Microsoft / visio2002 – 2002
- Microsoft / visio2002 – 2002
- Microsoft / visio2002 – 2002
- Microsoft / Word2002 – 2002
- Microsoft / Word2002 – 2002
- Microsoft / Word2002 – 2002
- Microsoft / Word2002 – 2002
- Microsoft / works2002 – 2002
- Microsoft / works2003 – 2003
- Microsoft / works2004 – 2004
References
- MISChttp://www.kb.cert.org/vuls/id/416001
- MISChttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-005
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2738
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2348
- MISChttp://www.us-cert.gov/cas/techalerts/TA05-039A.html
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4022
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/19107