Microsoft Word 2007 - Multiple Vulnerabilities

Related Vulnerabilities: CVE-2007-1911   CVE-2007-1910  
Publish Date: 09 Apr 2007
Author: muts
                							

                # Mati Aharoni

# muts [.@.] offensive-security.com

# http://www.offensive-security.com

 

 

My 7 line python fuzzer found several file format bugs in 3 hours. Quite alarming.

No deep analysis was done, I leave that to the community.

These are some of the results:

 

file789-1.doc  - Unspecified Overflow in word 2007 - Crash in wwlib.dll . Code execution is not trivial.

file798-1.doc . Word 2007 CPU exhaustion DOS - CPU shoots up to 100 %.

file613-1.doc -  Word 2007 CPU exhaustion DOS + ding - CPU shoots up to 100 %, and windows goes .ding!.

 

These files can be found at http://www.offensive-security.com/0day/0day.tar.gz

backup: https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/3690.tar.gz (04092007-0day.tar.gz)
 

Be safe,

 

Muts


# milw0rm.com [2007-04-09]