First published: Mon Jul 10 2006(Updated: )
Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office | =2003-sp1 | |
Microsoft Office | =xp-sp3 | |
Microsoft Office | =2000 | |
Microsoft Office | =2003-sp2 | |
Microsoft Office | =xp-sp2 | |
Microsoft Office | =2000-sp1 | |
Microsoft Office | =2000-sp2 | |
Microsoft Office | =2003 | |
Microsoft Office | =2003-sp3 | |
Microsoft Office | =xp | |
Microsoft Office | =xp-sp1 | |
Microsoft Office | =2000-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.