[prev in list] [next in list] [prev in thread] [next in thread] 

List:       full-disclosure
Subject:    Re: [Full-disclosure] Microsoft Office Publisher 2010 memory corruption
From:       Peter Ferrie <peter.ferrie () gmail ! com>
Date:       2012-10-29 1:48:23
Message-ID: CALX4979=ugV0TM2jnMSDgLNEnwq12SCu9-b55WFUvgZO7mLqnw () mail ! gmail ! com
[Download RAW message or body]

> I have discovered many crashes during testing MS product which i can
> discuss with authority  responsible
> memory corruption during the handling of the pub files a
> context-dependent attacker can execute arbitrary code.
> ----

> ecx=00000004 ... esi=00000000
...
> MSVCR90!memmove+0x140:
> 7855b450 8b448ef0        mov     eax,dword ptr [esi+ecx*4-10h]
> ds:0023:00000000=????????

This is a null pointer access.  You have not demonstrated any control
over the value in esi, so it is highly unlikely that it can be used
for exploitation.
We will investigate it, of course.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic