微软富文本格式(RTF)阅读器缓冲区溢出漏洞

微软富文本格式(RTF)阅读器缓冲区溢出漏洞

漏洞ID 1105613 漏洞类型 缓冲区溢出
发布时间 1999-11-17 更新时间 2005-07-27
图片[1]-微软富文本格式(RTF)阅读器缓冲区溢出漏洞-安全小百科CVE编号 CVE-2000-0073
图片[2]-微软富文本格式(RTF)阅读器缓冲区溢出漏洞-安全小百科CNNVD-ID CNNVD-199911-059
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/19633
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-199911-059
|漏洞详情
微软富文本格式(RTF)阅读器存在缓冲区溢出漏洞。攻击者可以通过一个畸形控制字引起服务拒绝。
|漏洞EXP
Windows 95/98,Windows NT Enterprise Server 4.0 SP1/SP2/SP3/SP4/SP5/SP6,Windows NT Server 4.0 SP1/SP2/SP3/SP4/SP5/SP6/SP6a,Windows NT Terminal Server 4.0 SP1/SP2/SP3/SP4/SP5/SP6,Windows NT Workstation 4.0 SP1/SP2/SP3/SP4/SP5/SP6/SP6a Riched Buffer Overflow Vulnerability

source: http://www.securityfocus.com/bid/807/info

Riched20.dll and Riched32.dll, which Windows uses to parse Rich Text Forrmat files, have an unchecked buffer which allows arbitrary code to be executed. The code can be put into an .rtf file and emailed to the victim. Then if the victim opens the document, the code will be run at the same privilege level as the user.

NOTE: It has been reported on the Bugtraq mailing list that the patch provided by Microsoft does not completely fix the problem. A .rtf file with 1000 characters (instead of the original 32) will still crash the application reading the .rtf file. 

This will crash Wordpad:
Create an .rtf file, then open it in notepad. The first line will look something like this:
{rtf1ansideff0deftab720{fonttbl...etc....etc
Now insert 32 characters after the .rtf identifier:
{rtf1AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAansideff0deftab720{fonttbl...etc...etc
When this file is opened in Wordpad, the program will crash.

https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/bin-sploits/19633.wri
|参考资料

来源:MS
名称:MS00-005
链接:http://www.microsoft.com/technet/security/bulletin/ms00-005.asp
来源:MSKB
名称:Q249973
链接:http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q249973
来源:XF
名称:win-malformed-rtf-control-word
链接:http://xforce.iss.net/search.php3?type=2&pattern;=win-malformed-rtf-control-word

相关推荐: Simple Message Board 2.0 beta1 – ‘User.cfm’ Cross-Site Scripting

Simple Message Board 2.0 beta1 – ‘User.cfm’ Cross-Site Scripting 漏洞ID 1055253 漏洞类型 发布时间 2005-07-14 更新时间 2005-07-14 CVE编号 N/A CNNVD…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享