[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: The newest Word flaw is due to malformed data structure handling

Juha-Matti Laurio wrote:
> Related to the newest MS Word 0-day
> http://blogs.technet.com/msrc/archive/2006/12/10/new-report-of-a-word-zero-day.aspx
> US-CERT Vulnerability Note VU#166700 released today lists the
> following new technical detail:
> "Microsoft Word fails to properly handle malformed data structures
> allowing memory corruption to occur."
> http://www.kb.cert.org/vuls/id/166700
> - Juha-Matti

  That's kind-of a truism, since word files basically /are/ serialised data 
structures.  Well, assuming we're not talking about some new xml format but 
native word .doc format.

Can't think of a witty .sigline today....