|
|
|
|
| |
Credit:
The information has been provided by Chaouki Bekrar.
The original article can be found at: http://seclists.org/bugtraq/2010/Dec/155
|
| |
Vulnerable Systems:
* Microsoft Publisher 2010 (32-bit editions)
* Microsoft Publisher 2010 (64-bit editions)
* Microsoft Publisher 2003 Service Pack 3
* Microsoft Publisher 2002 Service Pack 3
The vulnerability is caused by a memory corruption error when handling malformed Publisher documents, which could be exploited by remote attackers to execute arbitrary code by tricking a user into opening a malicious PUB file.
Note: The Publisher file format is not publicly documented.
Patch Availability:
Apply MS10-103 security updates:
http://www.microsoft.com/technet/security/bulletin/ms10-103.mspx
CVE Information:
CVE-2010-3954
Disclosure Timeline:
2010-03-18 - Vendor notified
2010-03-18 - Vendor response
2010-12-08 - Status update received
2010-12-14 - Coordinated disclosure
|
|
|
|
|