20030903 EEYE: Microsoft WordPerfect Document Converter Buffer Overflowmailing list
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0092.html CVE-2003-0666
Microsoft WordPerfect - Converter Buffer Overrun
Record summary
CVE-2003-0666 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.
Description
Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters in a Corel WordPerfect file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBMicrosoft WordPerfect - Converter Buffer OverrunExploitDB exploitby valgasuNot analyzed1 file
ExploitDBMicrosoft WordPerfect Document Converter (Windows NT4 Workstation SP5/SP6 French) - File Template Buffer Overflow (MS03-036)ExploitDB exploitby valgasuNot analyzed1 file
References
520030903 EEYE: Microsoft WordPerfect Document Converter Buffer Overflowmailing list
http://marc.info/?l=bugtraq&m=106261952827573&w=2 20030905 Microsoft WordPerfect Document Converter Exploitmailing list
http://marc.info/?l=bugtraq&m=106279971612961&w=2 MS03-036Vendor advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-036 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0666