---------------------------------------------------------------------- Do you have VARM strategy implemented? (Vulnerability Assessment Remediation Management) If not, then implement it through the most reliable vulnerability intelligence source on the market. Implement it through Secunia. For more information visit: http://secunia.com/advisories/business_solutions/ Alternatively request a call from a Secunia representative today to discuss how we can help you with our capabilities contact us at: sales@secunia.com ---------------------------------------------------------------------- TITLE: Microsoft Office Project Memory Validation Vulnerability SECUNIA ADVISORY ID: SA37588 VERIFY ADVISORY: http://secunia.com/advisories/37588/ DESCRIPTION: A vulnerability has been reported in Microsoft Office Project, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error when validating memory resource allocations during opening of a Project file. This can be exploited to corrupt memory via a specially crafted Project file. Successful exploitation may allow execution of arbitrary code. SOLUTION: Apply patches. Microsoft Project 2000 SR1: http://www.microsoft.com/downloads/details.aspx?familyid=135c010a-55f4-4385-b67d-96ea06ef881a Microsoft Project 2002 SP1: http://www.microsoft.com/downloads/details.aspx?familyid=c55ef8fe-8f66-42fc-a298-de6f8886b3e4 Microsoft Office Project 2003 SP3: http://www.microsoft.com/downloads/details.aspx?familyid=2ea8ca39-f130-439a-92d5-77e9ef050105 PROVIDED AND/OR DISCOVERED BY: The vendor credits Bing Liu, Fortinet's FortiGuard Labs. ORIGINAL ADVISORY: MS09-074 (KB961079, KB961082, KB961083, KB967183): http://www.microsoft.com/technet/security/Bulletin/MS09-074.mspx ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------