search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Microsoft Office WordPerfect 5.x Converter contains a buffer overflow vulnerability

Vulnerability Note VU#449438

Original Release Date: 2004-09-15 | Last Revised: 2004-09-17

Overview

A buffer overflow vulnerability in the Microsoft Office WordPerfect 5.x Converter could allow a remote attacker to execute arbitrary code on a vulnerable system.

Description

The Microsoft Office WordPerfect 5.x Converter allows users to convert documents in WordPerfect format to Microsoft Word format. The way the converter validates the length of a parameter before passing it to its allocated buffer creates a buffer overflow vulnerability. By convincing a victim to open a specially crafted WordPerfect 5.x document using the WordPerfect 5.x Converter, a remote attacker could trigger a buffer overflow.

According to the Microsoft Security Bulletin, the following software is affected:

    • Microsoft Office 2000 Software Service Pack 3
    • Microsoft Office XP Software Service Pack 3
    • Microsoft Office 2003
    • Microsoft Works Suites

Microsoft notes that Office 2003 Service Pack 1 is not affected by this vulnerability.

Impact

By convincing a victim to open a specially crafted WordPerfect 5.x document, a remote attacker could execute arbitrary code with the privileges of the vulnerable process.

Solution

Apply Patch
Apply a patch as described in Microsoft Security Bulletin MS04-027.


Workarounds
According to the Microsoft Security Bulletin, the following workarounds are recommended:

Do not open WordPerfect 5.x documents using the affected WordPerfect 5.x Converter.

Do not open WordPerfect 5.x documents from untrusted sources using any software listed as affected in this bulletin on systems that are not updated with the security updates that accompany this bulletin.

Uninstall the WordPerfect 5.x Converter.

Uninstall the WordPerfect 5.x Converter from your system through Add or Remove Programs. Choose a program from the Affected Software list that is installed on your system and click Change. The WordPerfect 5.x Converter is an Office Shared Feature.

Impact of workaround: Opening WordPerfect 5.x documents using any software listed in the Affected Software section would no longer be possible.

Use a third-party WordPerfect 5.x to Word converter or ask the user of WordPerfect to save the document in another format.

Vendor Information

449438
 

Microsoft Corporation Affected

Updated:  September 15, 2004

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

Please refer to Microsoft Security Bulletin MS04-027.

If you have feedback, comments, or additional information about this vulnerability, please send us email.


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was reported by Microsoft. Microsoft credits Peter Winter-Smith for discovering this vulnerability.

This document was written by Damon Morda based on information provided by Microsoft.

Other Information

CVE IDs: CVE-2004-0573
Severity Metric: 0.90
Date Public: 2004-09-14
Date First Published: 2004-09-15
Date Last Updated: 2004-09-17 13:42 UTC
Document Revision: 18

Sponsored by CISA.