|
|
|
|
| |
Credit:
The information has been provided by Microsoft Product Security.
The original article can be found at: http://www.microsoft.com/technet/security/bulletin/ms08-012.mspx
|
| |
Affected Software
Office Suite and Other Affected Software - Component - Maximum Security Impact - Aggregate Severity Rating - Bulletins Replaced by This Update
* Microsoft Office 2000 Service Pack 3 - Microsoft Office Publisher 2000 (KB946255) - Remote Code Execution - Critical - MS06-054
* Microsoft Office XP Service Pack 3 - Microsoft Office Publisher 2002 (KB946216) - Remote Code Execution - Important - MS06-054
* Microsoft Office 2003 Service Pack 2 - Microsoft Office Publisher 2003 Service Pack 2 (KB946254) - Remote Code Execution - Important - MS06-054
Non-Affected Software
Office Suite - Application
* 2007 Microsoft Office System - Microsoft Office Publisher 2007
* 2007 Microsoft Office System Service Pack 1 - Microsoft Office Publisher 2007 Service Pack 1
* Microsoft Office 2003 Service Pack 3 - Microsoft Office Publisher 2003 Service Pack 3
Publisher Invalid Memory Reference Vulnerability - CVE-2008-0102
A remote code execution vulnerability exists in the way Microsoft Office Publisher validates application data when loading Publisher files to memory. An attacker could exploit the vulnerability by constructing a specially crafted Publisher (.pub) file. When a user views the .pub file, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
CVE Information:
CVE-2008-0102
Publisher Memory Corruption Vulnerability - CVE-2008-0104
A remote code execution vulnerability exists in the way Microsoft Office Publisher validates memory index values. An attacker could exploit the vulnerability by constructing a specially crafted Publisher (.pub) file. When a user views the .pub file, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
CVE Information:
CVE-2008-0102
|
|
|
|
|