---------------------------------------------------------------------- Did you know that a change in our assessment rating, exploit code availability, or if an updated patch is released by the vendor, is not part of this mailing-list? Click here to learn more: http://secunia.com/advisories/business_solutions/ ---------------------------------------------------------------------- TITLE: Microsoft Office Visio Multiple Vulnerabilities SECUNIA ADVISORY ID: SA33833 VERIFY ADVISORY: http://secunia.com/advisories/33833/ CRITICAL: Highly critical IMPACT: System access WHERE: >From remote SOFTWARE: Microsoft Visio 2002 http://secunia.com/advisories/product/1091/ Microsoft Visio 2003 http://secunia.com/advisories/product/1092/ Microsoft Visio 2007 http://secunia.com/advisories/product/13229/ DESCRIPTION: Some vulnerabilities have been reported in Microsoft Office Visio, which can be exploited by malicious people to compromise a user's system. 1) An error when parsing object data during opening of Visio files can be exploited to corrupt memory via a specially crafted Visio file. 2) An error when copying object data in memory can be exploited to corrupt memory via a specially crafted Visio file. 3) An error in the handling of memory when opening Visio files can be exploited to corrupt memory via a specially crafted Visio file. Successful exploitation may allow execution of arbitrary code. SOLUTION: Apply patches. Microsoft Office Visio 2002 SP2: http://www.microsoft.com/downloads/details.aspx?familyid=a30cef3f-9eaf-45bd-9a25-4b65302362cb Microsoft Office Visio 2003 SP3: http://www.microsoft.com/downloads/details.aspx?familyid=c9cb589e-1a37-485d-8402-7f42bcd7a1a9 Microsoft Office Visio 2007 SP1: http://www.microsoft.com/downloads/details.aspx?familyid=4b711e89-8de2-4f17-8afc-691e0604ff82 PROVIDED AND/OR DISCOVERED BY: The vendor credits Bing Liu, Fortinet FortiGuard Global Security Research Team. ORIGINAL ADVISORY: MS09-005 (KB957634, KB955654, KB955655, KB957831): http://www.microsoft.com/technet/security/Bulletin/MS09-005.mspx ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------