Vulnerability Bulletins |
Múltiples vulnerabilidades en Microsoft Office Word |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Obtener acceso |
| Dificulty | Experto |
| Required attacker level | Acceso remoto sin cuenta a un servicio estandar |
System information |
|
| Property | Value |
| Affected manufacturer | Microsoft |
| Affected software | Microsoft Office Word 2000, XP, 2003, 2007 |
Description |
|
|
Se han descubierto múltiples vulnerabilidades en Microsoft Office Word. Las vulnerabilidades son descritas a continuación: - CVE-2009-0563: Se ha descubierto una vulnerabilidad de desbordamiento de búfer. Un atacante remoto podría ejecutar código arbitrario mediante un documento Word especialmente diseñado. - CVE-2009-0565: Se ha descubierto una vulnerabilidad de tipo desbordamiento de búfer. Un atacante remoto podría ekecutar código arbitrario mediante un documento Word con un registro erróneo que provoca corrupción de memoria. El boletín MS09-027 sustituye a los MS08-072 y MS08-074. |
|
Solution |
|
|
Actualización de software Microsoft (MS09-027) Microsoft Office 2000 Service Pack 3 / patch office2000-KB969600-FullFile-ENU Microsoft Office XP Service Pack 3 / patch officexp-KB969602-FullFile-ENU Microsoft Office 2003 Service Pack 3 / patch office2003-KB969603-FullFile-ENU 2007 Microsoft Office System / patch word2007-KB969604-fullfile-x86-glb 2007 Microsoft Office System Service Pack 2 / patch word2007-KB969604-fullfile-x86-glb Microsoft Office Word Viewer 2003 / patch office2003-KB969614-FullFile-ENU Microsoft Office Word Viewer 2003 Service Pack 3 / patch office2003-KB969614-FullFile-ENU Microsoft Office Compatibility Pack for Word, Excel, y PowerPoint 2007 File Formats SP1 y SP2 / patch office2007-KB969613-fullfile-x86-glb Microsoft Office 2004 for Mac / patch Office2004-1155UpdateEN Microsoft Office 2008 for Mac / patch Office2008-1219UpdateEN Open XML File Format Converter for Mac / patch OpenXMLConverter103 |
|
Standar resources |
|
| Property | Value |
| CVE |
CVE-2009-0563 CVE-2009-0565 |
| BID |
35188 35190 |
Other resources |
|
|
Microsoft Security Bulletin (MS09-027) http://www.microsoft.com/technet/security/Bulletin/MS09-027.mspx |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2009-06-15 |






