HTTP: Microsoft Office OneNote 2010 Buffer Size Validation

This signature detects attempts to exploit a known vulnerability against Microsoft Office OneNote 2010. A successful attack can lead to unauthorized information disclosure.

Extended Description

Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive information via a crafted OneNote file, aka "Buffer Size Validation Vulnerability."

Affected Products

Microsoft sharepoint_foundation

References

CVE: CVE-2013-0086

Short Name
HTTP:STC:DL:ONENOTE-INFO-DISC
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
2010 Buffer CVE-2013-0086 Microsoft Office OneNote Size Validation
Release Date
03/12/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Microsoft

CVSS Score

5.0

Found a potential security threat?