{"vuid":"VU#449438","idnumber":"449438","name":"Microsoft Office WordPerfect 5.x Converter contains a buffer overflow vulnerability","keywords":["Microsoft","WordPerfect 5.x Converter","Microsoft Office","Microsoft FrontPage","Microsoft Publisher","Microsoft Works Suite","MS04-027","Q884933"],"overview":"A buffer overflow vulnerability in the Microsoft Office WordPerfect 5.x Converter could allow a remote attacker to execute arbitrary code on a vulnerable system.","clean_desc":"The Microsoft Office WordPerfect 5.x Converter allows users to convert documents in WordPerfect format to Microsoft Word format. The way the converter validates the length of a parameter before passing it to its allocated buffer creates a buffer overflow vulnerability. By convincing a victim to open a specially crafted WordPerfect 5.x document using the WordPerfect 5.x Converter, a remote attacker could trigger a buffer overflow. According to the Microsoft Security Bulletin, the following software is affected: Microsoft Office 2000 Software Service Pack 3\nMicrosoft Office XP Software Service Pack 3\nMicrosoft Office 2003\nMicrosoft Works Suites Microsoft notes that Office 2003 Service Pack 1 is not affected by this vulnerability.","impact":"By convincing a victim to open a specially crafted WordPerfect 5.x document, a remote attacker could execute arbitrary code with the privileges of the vulnerable process.","resolution":"Apply Patch\nApply a patch as described in Microsoft Security Bulletin MS04-027.","workarounds":"Workarounds\nAccording to the Microsoft Security Bulletin, the following workarounds are recommended: Do not open WordPerfect 5.x documents using the affected WordPerfect 5.x Converter. Do not open WordPerfect 5.x documents from untrusted sources using any software listed as affected in this bulletin on systems that are not updated with the security updates that accompany this bulletin. Uninstall the WordPerfect 5.x Converter. Uninstall the WordPerfect 5.x Converter from your system through Add or Remove Programs. Choose a program from the Affected Software list that is installed on your system and click Change. The WordPerfect 5.x Converter is an Office Shared Feature. Impact of workaround: Opening WordPerfect 5.x documents using any software listed in the Affected Software section would no longer be possible. Use a third-party WordPerfect 5.x to Word converter or ask the user of WordPerfect to save the document in another format.","sysaffected":"","thanks":"This vulnerability was reported by Microsoft. Microsoft credits Peter Winter-Smith for discovering this vulnerability.","author":"This document was written by Damon Morda based on information provided by Microsoft.","public":["http://www.microsoft.com/technet/security/bulletin/MS04-027.mspx","http://secunia.com/advisories/12529/","http://www.securiteam.com/windowsntfocus/5RP0D1FE0A.html","http://www.securitytracker.com/alerts/2004/Sep/1011249.html","http://www.securitytracker.com/alerts/2004/Sep/1011250.html","http://www.securitytracker.com/alerts/2004/Sep/1011251.html","http://www.securitytracker.com/alerts/2004/Sep/1011252.html"],"cveids":["CVE-2004-0573"],"certadvisory":"","uscerttechnicalalert":null,"datecreated":"2004-09-14T18:12:11Z","publicdate":"2004-09-14T00:00:00Z","datefirstpublished":"2004-09-15T15:13:27Z","dateupdated":"2004-09-17T13:42:08Z","revision":18,"vrda_d1_directreport":"","vrda_d1_population":"","vrda_d1_impact":"","cam_widelyknown":"15","cam_exploitation":"0","cam_internetinfrastructure":"5","cam_population":"15","cam_impact":"4","cam_easeofexploitation":"2","cam_attackeraccessrequired":"20","cam_scorecurrent":"0.9","cam_scorecurrentwidelyknown":"1.125","cam_scorecurrentwidelyknownexploited":"2.025","ipprotocol":"","cvss_accessvector":"","cvss_accesscomplexity":"","cvss_authentication":null,"cvss_confidentialityimpact":"","cvss_integrityimpact":"","cvss_availabilityimpact":"","cvss_exploitablity":null,"cvss_remediationlevel":"","cvss_reportconfidence":"","cvss_collateraldamagepotential":"","cvss_targetdistribution":"","cvss_securityrequirementscr":"","cvss_securityrequirementsir":"","cvss_securityrequirementsar":"","cvss_basescore":"","cvss_basevector":"","cvss_temporalscore":"","cvss_environmentalscore":"","cvss_environmentalvector":"","metric":0.9,"vulnote":null}