Vulnerability in Microsoft RTF files

Network Security · 2000

Microsoft Security Bulletin MS00-005 reveals that there is a denial-of-service vulnerability where specially crafted data is used to exploit this vulnerability. RTF files consist of text and control information. The control information is specified via directives called control words. The default RTF reader that ships as part of many Windows platforms has an unchecked buffer in the portion of the reader that parses control words. If an RTF file contains a specially malformed control word it could cause the application to crash.

Read the paper · More papers on PaperTik