Users login

Create an account »

JOIN XATRIX

Users login

Home » Hacking News » Riched20.DLL attribute label buffer overflow vulnerability

Riched20.DLL attribute label buffer overflow vulnerability

by Nikola Strahija on February 18th, 2003 A buffer overflow vulnerability exists in riched20.dll,which can result in the collapse of the application program that use the corresponding function of the DLL module.


URL:http:\www.yoursft.com
Author: Thrkdev
finds dateF2003”N2ŒŽ1“ú
Announce dateF2003”N2ŒŽ14“ú

Affected system: Microsoft Windows 98
Microsoft Windows 2000
Microsoft Windows XP
Perhaps,this vulnerability was still in other operating
system, but untest .
EMAIL: [email protected]
------------------------------------------------------------------------
Technical description:
A buffer overflow vulnerability exists in riched20.dll,which can result
in the collapse
of the application program that use the corresponding function of the DLL
module, But it is
very difficult to have the effect of allowing an attacker to execute
commands on a userfs system.

This problem exists in the analysed RTF file code, and there is an
overflows when drawing
figure-string( such as the size of the character) in the file form .This
overflow seem not to
be used for executing commands.
The following RTFfile may result in illegal operation :
{rtf1ansiansicpg936deff0deflang1033deflangfe2052{fonttbl{f0
fnilfprq2fcharset134 'cb'ce'cc'e5;}}
{colortbl ;red255green0blue255;}
viewkind4uc1pardcf1kerning2f0
fs18121111111111111111111111111111111110000 www.yoursft.comfs20par
}
"fs" was used for setting the size of the followingly
words "www.yoursft.com". when the figure-string
that set the size of the fonts exceeding 1024byte(>1024b) , it Will cause
the buffer overflow ;And when
exceeding 65536byte(>65536b) it will probably cause crashing the
application program.
This promblom Not only appear in the setting of "fs" , other attribute
will have the same problem under
the similar situation. And this following RTF files Will also result in
operating illegally :
{rtf1ansiansicpg936deff0deflang1033deflangfe2052{fonttbl{f0
fnilfprq2fcharset134 'cb'ce'cc'e5;}}
{colortbl ;red255green0blue255;}
viewkind4uc1pardcf1kerning2f0121111111111111111111111111111111112222
fs180 www.yoursft.comfs20par
}
The terrible thing is nowadays lots of software was affected by this
vulnerability. The attacker can send a
malicious message that include exploiting the vulnerability, then when you
read this message your program will be crashed.

------------------------------------------------------------------------
Security Defence Stdio is a software development / technological websites,
mainly developing NET security products ,
the software of Security Defence Stdio --Trojan Ender-- receives users'
extensive favorable comment


Newsletter signup

Signup to our monthly newsletter and stay in touch with IT news!

Free E-books

We've got ebooks! But they're not online. :( Please give us a few days to bring downloads back.

Contact

Have something to say or just wanna drop us a line? Please keep this in mind: to spam, we reply with spam.

Contact us »