imPC@ndo IT

Tracker / CVE-2004-0848

CVE-2004-0848

High 7.5

Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.

Affected products and versions

microsoft office
microsoft powerpoint
microsoft project
microsoft visio
microsoft word
microsoft works

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References