Microsoft Windows winhlp32.exe buffer overflow
| win-winhlp32-bo (18678) |
Description:
Microsoft Windows are vulnerable to a buffer overflow in the winhlp32.exe executable when processing phrase offsets and the phrasesEndOffset parameter. By creating a specially-crafted .hlp file, a remote attacker could overflow a buffer and execute arbitrary code on the system, once the file is opened. An attacker could exploit this vulnerability by sending the malicious file to a victim as an email attachment or by hosting it on a Web page.
Consequences:
Gain Access
Remedy:
No remedy available as of July 9, 2011.
References:
- BugTraq Mailing List, Thu Dec 23 2004 - 09:00:42 CST: Microsoft Windows winhlp32.exe Heap Overflow Vulnerability.
- BID-12091: Microsoft Windows winhlp32 Phrase Integer Overflow Vulnerability
- BID-12092: Microsoft Windows winhlp32 Phrase Heap Overflow Vulnerability
- CVE-2004-1306: Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a crafted .hlp file.
- CVE-2004-1361: Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a malformed .hlp file, which leads to a heap-based buffer overflow.
- US-CERT VU#115632: Microsoft Windows help viewer vulnerable to heap overflow
Platforms Affected:
- Microsoft Windows 2000
- Microsoft Windows 2003 Server
- Microsoft Windows NT 4.0
- Microsoft Windows XP SP1
- Microsoft Windows XP SP2
Reported:
Dec 23, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
