HTTP: Microsoft Office Word and WordPerfect Converter Buffer Overflow

This signature detects attempts to exploit a known vulnerability in the Microsoft Office Word and WordPerfect Converter. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the client.

Extended Description

The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability."

References

BugTraq: 34469

CVE: CVE-2009-0088

Short Name
HTTP:STC:DL:WPD-BO
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Buffer CVE-2009-0088 Converter Microsoft Office Overflow Word WordPerfect and bid:34469
Release Date
10/05/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
CVSS Score

9.3

Found a potential security threat?