Secunia Security Advisory - Some vulnerabilities have been reported in Microsoft Office Visio, which can be exploited by malicious people to compromise a user's system.
6f09daf459f57fb764849d2f67cb82f199c2beb4af11e43f602d8a9568a61918
----------------------------------------------------------------------
Did you know that a change in our assessment rating, exploit code
availability, or if an updated patch is released by the vendor, is
not part of this mailing-list?
Click here to learn more:
http://secunia.com/advisories/business_solutions/
----------------------------------------------------------------------
TITLE:
Microsoft Office Visio Multiple Vulnerabilities
SECUNIA ADVISORY ID:
SA33833
VERIFY ADVISORY:
http://secunia.com/advisories/33833/
CRITICAL:
Highly critical
IMPACT:
System access
WHERE:
>From remote
SOFTWARE:
Microsoft Visio 2002
http://secunia.com/advisories/product/1091/
Microsoft Visio 2003
http://secunia.com/advisories/product/1092/
Microsoft Visio 2007
http://secunia.com/advisories/product/13229/
DESCRIPTION:
Some vulnerabilities have been reported in Microsoft Office Visio,
which can be exploited by malicious people to compromise a user's
system.
1) An error when parsing object data during opening of Visio files
can be exploited to corrupt memory via a specially crafted Visio
file.
2) An error when copying object data in memory can be exploited to
corrupt memory via a specially crafted Visio file.
3) An error in the handling of memory when opening Visio files can be
exploited to corrupt memory via a specially crafted Visio file.
Successful exploitation may allow execution of arbitrary code.
SOLUTION:
Apply patches.
Microsoft Office Visio 2002 SP2:
http://www.microsoft.com/downloads/details.aspx?familyid=a30cef3f-9eaf-45bd-9a25-4b65302362cb
Microsoft Office Visio 2003 SP3:
http://www.microsoft.com/downloads/details.aspx?familyid=c9cb589e-1a37-485d-8402-7f42bcd7a1a9
Microsoft Office Visio 2007 SP1:
http://www.microsoft.com/downloads/details.aspx?familyid=4b711e89-8de2-4f17-8afc-691e0604ff82
PROVIDED AND/OR DISCOVERED BY:
The vendor credits Bing Liu, Fortinet FortiGuard Global Security
Research Team.
ORIGINAL ADVISORY:
MS09-005 (KB957634, KB955654, KB955655, KB957831):
http://www.microsoft.com/technet/security/Bulletin/MS09-005.mspx
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------