MS03-036: Buffer Overrun In WordPerfect Convertor


Recommended Posts

-----BEGIN PGP SIGNED MESSAGE-----

- ----------------------------------------------------------------------

Title: Buffer Overrun in WordPerfect Converter Could Allow

Code Execution (827103)

Date: 03 September 2003

Software: Microsoft Office 97

Microsoft Office 2000

Microsoft Office XP

Microsoft Word 98 (J)

Microsoft FrontPage 2000

Microsoft FrontPage 2002

Microsoft Publisher 2000

Microsoft Publisher 2002

Microsoft Works Suite 2001

Microsoft Works Suite 2002

Microsoft Works Suite 2003

Impact: Run code of attacker's choice

Max Risk: Important

Bulletin: MS03-036

Microsoft encourages customers to review the Security Bulletins

at:

http://www.microsoft.com/technet/security/...in/MS03-036.asp

http://www.microsoft.com/security/security...ns/ms03-036.asp

- ----------------------------------------------------------------------

Issue:

======

Microsoft Office provides a number of converters that allow users

to import and edit files that use formats that are not native to

Office. These converters are available as part of the default

installation of Office and are also available separately in the

Microsoft Office Converter Pack. These converters can be useful

to organizations that use Office in a mixed environment with

earlier versions of Office and other applications, including

Office for the Macintosh and third-party productivity

applications.

There is a flaw in the way that the Microsoft WordPerfect

converter handles Corel® WordPerfect documents. A security

vulnerability results because the converter does not correctly

validate certain parameters when it opens a WordPerfect document,

which results in an unchecked buffer. As a result, an attacker

could craft a malicious WordPerfect document that could allow

code of their choice to be executed if an application that used

the WordPerfect converter opened the document. Microsoft Word and

Microsoft PowerPoint (which are part of the Office suite),

FrontPage (which is available as part of the Office suite or

separately), Publisher, and Microsoft Works Suite can all use the

Microsoft Office WordPerfect converter.

The vulnerability could only be exploited by an attacker who

persuaded a user to open a malicious WordPerfect document-there

is no way for an attacker to force a malicious document to be

opened or to trigger an attack automatically by sending an e-mail

message.

Mitigating Factors:

====================

- -The user must open the malicious document for an attacker to be

successful. An attacker cannot force the document to be opened

automatically.

- -The vulnerability cannot be exploited automatically through e-

mail. A user must open an attachment that is sent in an e-mail

message for an e-mail-borne attack to be successful.

Risk Rating:

============

- Important

Patch Availability:

===================

- A patch is available to fix this vulnerability. Please read

the Security Bulletins at

http://www.microsoft.com/technet/security/...in/ms03-036.asp

http://www.microsoft.com/security/security...ns/ms03-036.asp

for information on obtaining this patch.

Acknowledgment:

===============

- eEye Digital Security, http://www.eeye.com

- -----------------------------------------------------------------

- ----

Edited by xStainDx
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Movavi Video Editor Plus 25.12.0 by Razvan Serea With Movavi Video Editor, you can either enhance your video files with two or three simple steps, or turn them into something completely new. Create your own movies using multiple filters, transitions, and special effects: show multiple videos on one screen with the Picture in picture effect or change the background with the Chroma Key effect, imitate the camera zoom or make your video look like an old-style movie. Adjust video parameters such as brightness, contrast and colors. Stabilize shaky footage, improve video quality and remove defects. Create video presentations, tutorials or educational videos: add titles and record your own narration to create a video with voiceover. Import video from any source: TV-tuner, webcam, camcorder, or VHS. Drop multiple media files onto a timeline and let your imagination do the rest! Features at a glance: Video and audio editing on a timeline Edit, enhance videos Add background music Apply titles and effects Image quality improvement Hollywood-worthy effects High-grade titles and fades Digitize VHS tapes, record video from TV tuners Stabilize any shaky sections Support for a wide range of formats Prepare your videos for uploading to YouTube, Facebook, Vimeo, or any other website New in Movavi Video Editor 2025: Revamped timeline for easier editing The new timeline is now clearer and more streamlined. Get your projects done faster and have more fun with anything – from short vids for socials to longer family movies. Frame-precise cuts in a click Give your videos a sharper look with the new Blade tool. Easily make precise cuts and create eye-catching montages like your favorite bloggers. Pro-quality color correction Get next-level color correction with the same simplicity. Boost colors in a snap and make more viewers fall in love with your videos. AI motion tracking Enhance reality in your videos with additional moving graphics. Just click, and AI will quickly attach any photos, videos, emojis, or memes to objects in your footage. Perfect-match overlay effects Now each overlay effect has 13 blending modes to choose from. Try each of them with the press of a button and pick the one that fits your video perfectly. Best video effects – at your fingertips Create awesome videos in any style with our huge collection of professionally designed effects. Now you can try them all right away, right in the app. Movavi Video Editor 25.12.0 changelog: Just a minor upgrade to keep everything running smoothly. Download: Movavi Video Editor Plus 25.12.0 | 5.1 MB (Shareware) View: Movavi Video Editor Plus Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Major Privacy 0.98.3 Beta by Razvan Serea MajorPrivacy is a cutting-edge privacy and security tool for Windows, offering unparalleled control over process behavior, file access, and network communication. It is a continuation of the PrivateWin10 project. By leveraging advanced kernel-level protections, MajorPrivacy creates a secure environment where user data and system integrity are fully safeguarded. Unlike traditional tools, MajorPrivacy introduces innovative protection methods that ensure mounted encrypted volumes are only accessible by authorized applications, making it the first and only encryption solution of its kind. MajorPrivacy – Ultimate Privacy & Security for Windows key features Process Protection – Isolate processes to block interference from unauthorized apps, even with admin privileges. Software Restriction – Block unwanted apps and DLLs to ensure only trusted software runs. Revolutionary Encrypted Volumes Secure Storage – Create encrypted disk images for sensitive data. Exclusive Access – Unlike traditional tools, only authorized apps can access mounted volumes—blocking all unauthorized processes. File & Folder Protection – Lock down sensitive files and prevent unauthorized access or modifications. Advanced Network Firewall – Control which apps can send or receive data online. DNS Monitoring & Filtering – Track domain access and block unwanted sites (Pi-hole compatible filtering coming soon). Tweak Engine – Disable telemetry, cloud integration, and invasive Windows features for better privacy. Why MajorPrivacy? Kernel-Level Security – Protects at the deepest system level. Unmatched Encryption Protection – Keeps mounted volumes safe from all unauthorized access. Full System Control – Block, isolate, or restrict processes as needed. Enhanced Privacy – Stops Windows & apps from collecting unnecessary data. Perfect for privacy-conscious users, IT pros, and anyone who wants total system control. Major Privacy 0.98.3 Beta changelog: This release of MajorPrivacy introduces several important improvements, bug fixes, and optimizations. The resource access rules engine has been enhanced to include the user as an additional parameter, enabling finer-grained access control. CPU usage has been reduced in both the user interface and background service, improving overall performance. The ImBox feature has been updated to avoid modifying container file timestamps when accessing secure encrypted volumes. Firewall rule handling has been improved for Store Apps on Windows 23H2 and later versions, increasing compatibility and reliability. A critical issue has been resolved in ImBox.exe that affects the mounting of older encrypted volumes; users should use a previous build to recover data and then recreate the volumes using this or a later version. Additionally, several interface and functionality bugs have been addressed: translations now load correctly, the Data Editor’s tree view now functions properly across multiple .dat files, and the Execution Monitor displays entries as expected when a time filter is applied. The “Add to Group” menu now correctly lists all available groups, and folder creation is no longer incorrectly permitted under Directory Listing and Read-only actions. Download: Major Privacy 0.98.3 Beta | 59.4 MB (Open Source) View: MajorPrivacy Home Page | Github Project page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Hi there! Great question and yes, the Twenty Twenty-Four theme (TT4) + Gutenberg does have a few quirks when it comes to spacing and columns. To reduce the spacing between the image and the text in a two-column layout, here are a few things to try:  1. Adjust Block Spacing (Direct Method) Click on the Column Block (the outer wrapper that holds both your image and text). In the right sidebar, under "Block" > "Dimensions", look for the "Block spacing" setting (sometimes called “Gap”). Reduce the value (in px, em, or %) to tighten the space between elements inside that column. 2. Use Padding & Margin Controls Click on the Image block, and then the Text block individually. Under “Dimensions”, adjust the Margin of the Image or Text block (especially bottom or top margin) to reduce extra white space. Try setting margins to 0 or a small number like 8px. 3. Use Group Block (Optional) If the spacing controls aren’t behaving: Wrap the image + text inside a Group block. Then apply padding/margin settings to the inner blocks for better control.
    • Looks interesting, I love the art style. How many people are working on the game?
  • Recent Achievements

    • Reacting Well
      water01 earned a badge
      Reacting Well
    • First Post
      Aidan Helfrich earned a badge
      First Post
    • Collaborator
      bullgod69 earned a badge
      Collaborator
    • Enthusiast
      Ed B went up a rank
      Enthusiast
    • Reacting Well
      Xinotema earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      764
    2. 2
      ATLien_0
      187
    3. 3
      +FloatingFatMan
      151
    4. 4
      Xenon
      118
    5. 5
      wakjak
      113
  • Tell a friend

    Love Neowin? Tell a friend!