Microsoft Publisher Font Parsing Remote Code Execution Vulnerability
BID:19951
Info
Microsoft Publisher Font Parsing Remote Code Execution Vulnerability
| Bugtraq ID: | 19951 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-0001 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2006 12:00AM |
| Updated: | Oct 13 2006 09:49PM |
| Credit: | Stuart Pearson of Computer Terrorism reported this issue to the vendor. |
| Vulnerable: |
Microsoft Publisher 2003 Microsoft Publisher 2002 Microsoft Publisher 2000 Microsoft Office XP SP3 Microsoft Office XP SP2 Microsoft Office XP SP1 Microsoft Office XP Microsoft Office 2003 SP2 Microsoft Office 2003 SP1 Microsoft Office 2003 0 Microsoft Office 2000 SP3 Microsoft Office 2000 SP1 Microsoft Office 2000 Microsoft Internet Explorer for Unix SP2 HP Storage Management Appliance 2.1 |
| Not Vulnerable: | |
Discussion
Microsoft Publisher Font Parsing Remote Code Execution Vulnerability
Microsoft Publisher is prone to a code-execution vulnerability. This is due to a flaw when handling malformed PUB files.
Successfully exploiting this issue allows attackers to corrupt process memory and to execute arbitrary code in the context of targeted users.
Microsoft Publisher is prone to a code-execution vulnerability. This is due to a flaw when handling malformed PUB files.
Successfully exploiting this issue allows attackers to corrupt process memory and to execute arbitrary code in the context of targeted users.
Exploit / POC
Microsoft Publisher Font Parsing Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Publisher Font Parsing Remote Code Execution Vulnerability
Solution:
Microsoft has released a security advisory addressing this issue.
Microsoft Publisher 2003
Microsoft Publisher 2000
Microsoft Publisher 2002
Solution:
Microsoft has released a security advisory addressing this issue.
Microsoft Publisher 2003
-
Microsoft Security Update for Publisher 2003 (KB894542)
http://www.microsoft.com/downloads/details.aspx?familyid=2EEB43F1-E2B6 -4B78-98A1-E8B04242438A
Microsoft Publisher 2000
-
Microsoft Security Update for Publisher 2000 (KB894540)
http://www.microsoft.com/downloads/details.aspx?familyid=461A126B-596F -4E84-99FD-03554AC55213
Microsoft Publisher 2002
-
Microsoft Security Update for Publisher 2002 (KB894541)
http://www.microsoft.com/downloads/details.aspx?familyid=0356B9FB-2CD5 -4A50-95F6-54846D39B6EA
References
Microsoft Publisher Font Parsing Remote Code Execution Vulnerability
References:
References: