[NT] Microsoft Excel COLINFO Record Buffer Overflow (MS06-037)



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



Microsoft Excel COLINFO Record Buffer Overflow (MS06-037)
------------------------------------------------------------------------


SUMMARY

A buffer overflow vulnerability in Microsoft Excel's processing of COLINFO
record, which allows remote attackers to run arbitrary via carefully
crafted Excel files.

DETAILS

Vulnerable Systems:
* Microsoft Excel 2000
* Microsoft Excel 2002
* Microsoft Excel 2003

Excel does not perform sufficient check for certain field when processing
COLINFO record, which might cause a buffer overflow vulnerability in data
filling operation. Attackers can run arbitrary via carefully craft data.

Attackers can craft an Excel file with malformed COLINFO record and allure
users to open it via instant messaging tools, e-mail or other vectors,
resulting in arbitrary code execution with the privilege of the user. If
the user is the administrator, then attackers might take complete control
over the system.

CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1304>
CVE-2006-1304

Disclosure Timeline:
2006.03.30 Informed the vendor
2006.04.03 Vendor confirmed the vulnerability
2006.07.11 Microsoft has released a security bulletin (MS06-037) and
related patches.


ADDITIONAL INFORMATION

The information has been provided by <mailto:security@xxxxxxxxxxx>
NSFOCUS Security Team .
The original article can be found at:
<http://www.nsfocus.com/english/homepage/research/0606.htm>
http://www.nsfocus.com/english/homepage/research/0606.htm



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • SecurityFocus Microsoft Newsletter #366
    ... CSI 2007, November 3-9 in Washington, DC, is the only conference that delivers a business-focused overview of enterprise security. ... Mono System.Math BigInteger Buffer Overflow Vulnerability ... Ipswitch IMail SMTP Server IMail Client Remote Buffer Overflow Vulnerability ... Successfully exploiting this issue could allow attackers to execute arbitrary code in the context of the user running an affected application. ...
    (Focus-Microsoft)
  • [NT] Microsoft Visual Basic for Applications Multiple Vulnerabilities (MS08-057)
    ... Get your security news from a reliable source. ... Microsoft Excel 2000 SP3 ... attacker must persuade a user to open a specially crafted Office document. ... This allows attackers to exploit this vulnerability without user ...
    (Securiteam)
  • [NT] Microsoft Excel SELECTION Record Memory Corruption (MS06-037)
    ... Get your security news from a reliable source. ... Microsoft Excel SELECTION Record Memory Corruption ... SELECTION record allows remote attackers to run arbitrary via carefully ... This bulletin is sent to members of the SecuriTeam mailing list. ...
    (Securiteam)
  • Re: Memories of BoaterDave from 2006
    ... If no-one cares, Ari, why are our 'leaders' allowing our troops being ... Just like real-world security, the ... some attackers are highly skilled and motivated with the goal ...
    (alt.computer.security)
  • [NEWS] Vulnerability Enables Passport Account Hijackings (No Secret Question)
    ... Beyond Security in Canada ... to promote the most advanced vulnerability assessment solutions today. ... A newly disclosed vulnerability could enable attackers to reset the ... who needs to reset his account password can be manipulated by attackers on ...
    (Securiteam)