Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.

Project Subscriptions

Vendors Products
Microsoft Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://archives.neohapsis.com/archives/fulldisclosure/2006-08/0597.html cve-icon cve-icon
http://blogs.securiteam.com/?author=28 cve-icon cve-icon
http://blogs.securiteam.com/?p=557 cve-icon cve-icon
http://blogs.securiteam.com/?p=559 cve-icon cve-icon
http://isc.sans.org/diary.php?storyid=1618 cve-icon cve-icon
http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049540.html cve-icon cve-icon
http://secunia.com/advisories/19138 cve-icon cve-icon
http://secunia.com/advisories/19238 cve-icon cve-icon
http://securitytracker.com/id?1015766 cve-icon cve-icon
http://securitytracker.com/id?1016720 cve-icon cve-icon
http://securitytracker.com/id?1016886 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2006-069.htm cve-icon cve-icon
http://www.darkreading.com/document.asp?doc_id=101970 cve-icon cve-icon
http://www.kb.cert.org/vuls/id/682820 cve-icon cve-icon
http://www.osvdb.org/23903 cve-icon cve-icon
http://www.securityfocus.com/archive/1/427671/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/432004/30/5340/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/443890/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/444051/100/200/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/446370/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/446425/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/17000 cve-icon cve-icon
http://www.securityfocus.com/bid/20059 cve-icon cve-icon
http://www.symantec.com/enterprise/research/SYMSA-2006-001.txt cve-icon cve-icon
http://www.symantec.com/security_response/writeup.jsp?docid=2006-091810-5028-99 cve-icon cve-icon
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_MDROPPER.BH cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA06-073A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/0950 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3678 cve-icon cve-icon
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-012 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/25009 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/29009 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1504 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1553 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1653 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A798 cve-icon cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2024-08-07T16:18:20.667Z

Reserved: 2005-11-09T00:00:00

Link: CVE-2006-0009

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2006-03-14T23:02:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2006-0009

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses