Microsoft Visio Version Number Remote Code Execution Vulnerability

TITLE: Microsoft Visio Version Number Remote Code Execution Vulnerability
CLASS: Input Validation Error
CVE: CVE-2007-0934

REMOTE: Yes
LOCAL: No
PUBLISHED: Jun 12 2007 12:00AM
UPDATE: Jun 12 2007 12:00AM
CREDIT: The vendor disclosed this issue.
VULNERABLE:

Microsoft Visio 2003 SP2
Microsoft Visio 2003 SP1
Microsoft Visio 2003
Microsoft Visio 2002 SP2
Microsoft Visio 2002 SP1
Microsoft Visio 2002
NOT VULNERABLE:
Microsoft Visio Standard 2007 0
Microsoft Visio Professional 2007 0

Vai alla pagina originale su Security Focus

Discussion

Microsoft Visio is prone to a remote code-execution vulnerability because it fails to adequately validate user-supplied data.

Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Failed attempts will result in denial-of-service conditions.

Exploit

Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:vuldb@securityfocus.com.

Solution

Solution:
Microsoft has released advisory MS07-030 as well as fixes to address this issue. Please see the references for more information.


Microsoft Visio 2002


Microsoft Visio 2002 SP1

Microsoft Visio 2003

Microsoft Visio 2003 SP1

Microsoft Visio 2002 SP2

Microsoft Visio 2003 SP2

References

References:

PhpLog

BNLug Benevento Linux Users Group