Microsoft Visio Version Number Remote Code Execution Vulnerability
TITLE: Microsoft Visio Version Number Remote Code Execution Vulnerability
CLASS: Input Validation Error
CVE: CVE-2007-0934
REMOTE: Yes
LOCAL: No
PUBLISHED: Jun 12 2007 12:00AM
UPDATE: Jun 12 2007 12:00AM
CREDIT: The vendor disclosed this issue.
VULNERABLE:
Microsoft Visio 2003 SP2NOT VULNERABLE:
Microsoft Visio 2003 SP1
Microsoft Visio 2003
Microsoft Visio 2002 SP2
Microsoft Visio 2002 SP1
Microsoft Visio 2002
Microsoft Visio Standard 2007 0
Microsoft Visio Professional 2007 0
Vai alla pagina originale su Security Focus
Discussion
Microsoft Visio is prone to a remote code-execution vulnerability because it fails to adequately validate user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Failed attempts will result in denial-of-service conditions.
Exploit
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:vuldb@securityfocus.com.
Solution
Solution:
Microsoft has released advisory MS07-030 as well as fixes to address this issue. Please see the references for more information.
Microsoft Visio 2002
- Microsoft Security Update for Visio 2002 (KB927051)
http://www.microsoft.com/downloads/details/aspx?FamilyId=FC1D0483-27E8-4541-B81D-4A47973BEA30
Microsoft Visio 2002 SP1
- Microsoft Security Update for Visio 2002 (KB927051)
http://www.microsoft.com/downloads/details/aspx?FamilyId=FC1D0483-27E8-4541-B81D-4A47973BEA30
Microsoft Visio 2003
- Microsoft Security Update for Visio 2003 (KB927051)
http://www.microsoft.com/downloads/details.aspx?FamilyId=C47F432E-8538-42FD-92C9-7E0F1D643E8E&displaylang=en
Microsoft Visio 2003 SP1
- Microsoft Security Update for Visio 2003 (KB927051)
http://www.microsoft.com/downloads/details.aspx?FamilyId=C47F432E-8538-42FD-92C9-7E0F1D643E8E&displaylang=en
Microsoft Visio 2002 SP2
- Microsoft Security Update for Visio 2002 (KB927051)
http://www.microsoft.com/downloads/details/aspx?FamilyId=FC1D0483-27E8-4541-B81D-4A47973BEA30
Microsoft Visio 2003 SP2
- Microsoft Security Update for Visio 2003 (KB927051)
http://www.microsoft.com/downloads/details.aspx?FamilyId=C47F432E-8538-42FD-92C9-7E0F1D643E8E&displaylang=en
References
References:
- Visio Homepage (Microsoft)
- Microsoft Security Bulletin MS07-030 (Microsoft)