Secunia Advisory SA38805Microsoft Office Excel Multiple Vulnerabilities
|
||||
Description
Multiple vulnerabilities have been reported in Microsoft Office Excel, which can be exploited by malicious people to compromise a user's system. 1) An error in the parsing of records can be exploited to corrupt memory via a specially crafted file. 2) An error in the parsing of sheet object types can be exploited to corrupt memory via a specially crafted file. 3) An error in the parsing of MDXTUPLE records can be exploited to cause a heap-based buffer overflow via a specially crafted file. 4) An error in the parsing of MDXSET records can be exploited to cause a heap-based buffer overflow via a specially crafted file. 5) An error in the parsing of FNGROUPNAME records may result in the use of uninitialised memory via a specially crafted file. 6) An error in the parsing of a ZIP header within XLSX files when decompressing certain XML elements may result in use of uninitialised memory. 7) An error in the parsing of DbOrParamQry records can be exploited to corrupt memory via a specially crafted file. Successful exploitation of the vulnerabilities may allow execution of arbitrary code. Solution Provided and/or discovered by Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||
Fedora update for samba |
Debian update for tdiary |