Microsoft Publisher Memory Object Handler Data Remote Code Execution Vulnerability
BID:29158
Info
Microsoft Publisher Memory Object Handler Data Remote Code Execution Vulnerability
| Bugtraq ID: | 29158 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0119 |
| Remote: | Yes |
| Local: | No |
| Published: | May 13 2008 12:00AM |
| Updated: | May 14 2008 09:05PM |
| Credit: | Cocoruder of Fortinet Security Research |
| Vulnerable: |
Microsoft Publisher 2007 SP1 Microsoft Publisher 2007 0 Microsoft Publisher 2003 SP3 Microsoft Publisher 2003 SP2 Microsoft Publisher 2002 SP3 Microsoft Publisher 2000 SP3 |
| Not Vulnerable: | |
Discussion
Microsoft Publisher Memory Object Handler Data Remote Code Execution Vulnerability
Microsoft Publisher is prone to a remote code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to open a malicious Publisher file.
Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
Microsoft Publisher is prone to a remote code-execution vulnerability.
An attacker could exploit this issue by enticing a victim to open a malicious Publisher file.
Successfully exploiting this issue would allow the attacker to execute arbitrary code in the context of the currently logged-in user.
Exploit / POC
Microsoft Publisher Memory Object Handler Data Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Publisher Memory Object Handler Data Remote Code Execution Vulnerability
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Microsoft Publisher 2000 SP3
Microsoft Publisher 2003 SP3
Microsoft Publisher 2007 SP1
Microsoft Publisher 2002 SP3
Microsoft Publisher 2007 0
Microsoft Publisher 2003 SP2
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Microsoft Publisher 2000 SP3
-
Microsoft Security Update for Microsoft Publisher 2000 (KB950682)
http://www.microsoft.com/downloads/details.aspx?FamilyId=8675b9b6-fbf0 -4ad2-9210-285e2cc10556
Microsoft Publisher 2003 SP3
-
Microsoft Security Update for Microsoft Office Publisher 2003 (KB950213)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c18b060b-9828 -4952-8e80-5328c0832d83&displaylang=en
Microsoft Publisher 2007 SP1
-
Microsoft Security Update for Microsoft Office Publisher 2007 (KB950114)
http://www.microsoft.com/downloads/details.aspx?FamilyId=e4b647c2-79a3 -49e0-9b1d-741667fdbcca&displaylang=en
Microsoft Publisher 2002 SP3
-
Microsoft Security Update for Microsoft Publisher 2002 (KB950129)
http://www.microsoft.com/downloads/details.aspx?FamilyId=df623784-6e26 -42c0-9e21-e7960b849e1e&displaylang=en
Microsoft Publisher 2007 0
-
Microsoft Security Update for Microsoft Office Publisher 2007 (KB950114)
http://www.microsoft.com/downloads/details.aspx?FamilyId=e4b647c2-79a3 -49e0-9b1d-741667fdbcca&displaylang=en
Microsoft Publisher 2003 SP2
-
Microsoft Security Update for Microsoft Office Publisher 2003 (KB950213)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c18b060b-9828 -4952-8e80-5328c0832d83&displaylang=en
References
Microsoft Publisher Memory Object Handler Data Remote Code Execution Vulnerability
References:
References:
- Publisher Homepage (Microsoft)
- Microsoft Office Publisher PUB File Parsing Remote Memory Corruption Vulnerabili (cocoruder
) - Microsoft Security Bulletin MS08-027 - Critical (Microsoft)