Thursday, December 14, 2006
Detail on the latest Word vulnerability
"Data used by Microsoft Word to construct a destination address for a memory copy routine is embedded within a Word document itself. If an attacker constructs a Word document with a specially crafted value used to build this destination address, then that attacker may be able to overwrite arbitrary memory."
My brain hurts. Either this statement is trivially vacucous (the whole idea of file formats being to fill things into memory locations) or it reflects a truly bizarre design choice.
My brain hurts. Either this statement is trivially vacucous (the whole idea of file formats being to fill things into memory locations) or it reflects a truly bizarre design choice.