Oval Definition:oval:org.mitre.oval:def:5893
Revision Date:2014-06-30Version:12
Title:WordPad Word 97 Text Converter Stack Overflow Vulnerability
Description:Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an unspecified length field, aka "WordPad Word 97 Text Converter Stack Overflow Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2009-0235
Platform(s):Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows XP
Product(s):
Definition Synopsis
  • Windows 2000 SP4
  • Microsoft Windows 2000 SP4 or later is installed
  • AND the version of wordpad.exe is less than 5.0.2195.7155
  • OR Windows XP SP2
  • Microsoft Windows XP (x86) SP2 is installed
  • AND the version of wordpad.exe is less than 5.1.2600.3355
  • OR Windows XP SP3
  • Microsoft Windows XP (x86) SP3 is installed
  • AND the version of wordpad.exe is less than 5.1.2600.5584
  • OR Windows XP SP1/Server 2003 SP1
  • Windows XP SP1/Server 2003 SP1
  • Microsoft Windows XP Professional x64 Edition SP1 is installed
  • OR Microsoft Windows Server 2003 SP1 (x64) is installed
  • OR Microsoft Windows Server 2003 SP1 (x86) is installed
  • OR Microsoft Windows Server 2003 SP1 for Itanium is installed
  • AND the version of wordpad.exe is less than 5.2.3790.3129
  • OR Windows XP SP2/Server 2003 SP2
  • Windows XP SP2/Server 2003 SP2
  • Microsoft Windows XP x64 Edition SP2 is installed
  • OR Microsoft Windows Server 2003 SP2 (x64) is installed
  • OR Microsoft Windows Server 2003 SP2 (x86) is installed
  • OR Microsoft Windows Server 2003 (ia64) SP2 is installed
  • AND the version of wordpad.exe is less than 5.2.3790.4282
  • BACK