Microsoft Publisher File Conversion Textbox Remote Buffer Overflow Vulnerability
BID:39347
Info
Microsoft Publisher File Conversion Textbox Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 39347 |
| Class: | Unknown |
| CVE: |
CVE-2010-0479 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 13 2010 12:00AM |
| Updated: | Apr 22 2010 03:43PM |
| Credit: | Lionel d'Hauenen working with TippingPoint�??s Zero Day Initiative |
| Vulnerable: |
Microsoft Publisher 2007 SP2 Microsoft Publisher 2007 SP1 Microsoft Publisher 2007 0 Microsoft Publisher 2003 SP3 Microsoft Publisher 2003 SP2 Microsoft Publisher 2003 Microsoft Publisher 2002 SP3 Microsoft Publisher 2002 |
| Not Vulnerable: | |
Discussion
Microsoft Publisher File Conversion Textbox Remote Buffer Overflow Vulnerability
Microsoft Publisher is prone to a remote buffer-overflow vulnerability.
An attacker can exploit this issue by enticing a victim to open a malicious Publisher file.
Successfully exploiting this issue would allow an attacker to execute arbitrary code in the context of the currently logged-in user.
Microsoft Publisher is prone to a remote buffer-overflow vulnerability.
An attacker can exploit this issue by enticing a victim to open a malicious Publisher file.
Successfully exploiting this issue would allow an attacker to execute arbitrary code in the context of the currently logged-in user.
Exploit / POC
Microsoft Publisher File Conversion Textbox Remote Buffer Overflow Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Publisher File Conversion Textbox Remote Buffer Overflow Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Publisher 2003 SP3
Microsoft Publisher 2007 SP1
Microsoft Publisher 2002 SP3
Microsoft Publisher 2007 SP2
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Publisher 2003 SP3
-
Microsoft Security Update for Microsoft Office Publisher 2003 (KB980469)
http://www.microsoft.com/downloads/details.aspx?familyid=7c2f4610-77bb -4d72-847b-1a06c523b137
Microsoft Publisher 2007 SP1
-
Microsoft Security Update for Microsoft Office Publisher 2007 (KB980470)
http://www.microsoft.com/downloads/details.aspx?familyid=10ca2f71-0ab2 -4344-b7fd-bbbd6a783a96
Microsoft Publisher 2002 SP3
-
Microsoft Security Update for Microsoft Publisher 2002 (KB980466)
http://www.microsoft.com/downloads/details.aspx?familyid=943b3830-70d5 -46c5-bffc-1b494434b5f7
Microsoft Publisher 2007 SP2
-
Microsoft Security Update for Microsoft Office Publisher 2007 (KB980470)
http://www.microsoft.com/downloads/details.aspx?familyid=10ca2f71-0ab2 -4344-b7fd-bbbd6a783a96
References
Microsoft Publisher File Conversion Textbox Remote Buffer Overflow Vulnerability
References:
References:
- Publisher Homepage (Microsoft)
- ZDI-10-069: Microsoft Office Publisher File Conversion TextBox Processing Buffer (Zero Day Initiative)
- Microsoft Security Bulletin MS10-023 (Microsoft)