RULE(RULE ID:305090)

Rule General Information
Release Date: 2014-03-24
Rule Name: Microsoft Office XP URL Handling Buffer Overflow Vulnerability (CVE-2004-0848)
Severity:
CVE ID:
Rule Protection Details
Description: Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%%00" (null byte) in .doc filenames or (2) "%%0a" (carriage return) in .rtf filenames.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks include arbitrary code execution and denial of service.
Affected OS: Solaris, FreeBSD, Windows, Linux, Other Unix, Others
Reference: MicrosoftSecurityBulletin:ms05-005
Solutions
Microsoft has released a patch MS05-005 to eliminate the vulnerability. The patch can be downloaded at http://www.microsoft.com/technet/security/bulletin/ms05-005.mspx