Re: The newest Word flaw is due to malformed data structure handling

2006-12-14 Thread Juha-Matti Laurio
And without any reasonable technical details it is very difficult to give a title field for the vulnerability. Several advisories using titles like Word Unspecified Code Execution Vulnerability or Word Code Execution Vulnerability #2, #3 are not the trend we want. Related to the newest Word iss

Re: The newest Word flaw is due to malformed data structure handling

2006-12-14 Thread Steven M. Christey
Alexander Sotirov said: >Descriptions of vulnerabilities, especially ones that are found in the >wild, should include enough information to allow researchers to >uniquely identify the new vulnerability and differentiate it from all >other bugs, both known ones and 0days. I say this periodically,

Re: Re: The newest Word flaw is due to malformed data structure handling

2006-12-12 Thread test
Try this: http://www.milw0rm.com/sploits/12122006-djtest.doc

Re: The newest Word flaw is due to malformed data structure handling

2006-12-12 Thread Dave \"No, not that one\" Korn
Juha-Matti Laurio wrote: > Related to the newest MS Word 0-day > http://blogs.technet.com/msrc/archive/2006/12/10/new-report-of-a-word-zero-day.aspx > > US-CERT Vulnerability Note VU#166700 released today lists the > following new technical detail: > "Microsoft Word fails to properly handle malform

Re: The newest Word flaw is due to malformed data structure handling

2006-12-12 Thread Alexander Sotirov
Juha-Matti Laurio wrote: > Related to the newest MS Word 0-day > http://blogs.technet.com/msrc/archive/2006/12/10/new-report-of-a-word-zero-day.aspx > > US-CERT Vulnerability Note VU#166700 released today lists the following > new technical detail: > > "Microsoft Word fails to properly handle mal

The newest Word flaw is due to malformed data structure handling

2006-12-11 Thread Juha-Matti Laurio
Related to the newest MS Word 0-day http://blogs.technet.com/msrc/archive/2006/12/10/new-report-of-a-word-zero-day.aspx US-CERT Vulnerability Note VU#166700 released today lists the following new technical detail: "Microsoft Word fails to properly handle malformed data structures allowing memor