PT-2006-1097 · Microsoft · Office Publisher
Stuart Pearson
·
Published
2006-09-12
·
Updated
2018-10-19
·
CVE-2006-0001
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Microsoft Publisher versions 2000 through 2003
Description:
A stack-based buffer overflow issue allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts. This is related to a remote code execution issue that occurs when Publisher parses a file with a malformed string.
Recommendations:
For Microsoft Publisher versions 2000 through 2003, consider avoiding the use of crafted PUB files until a patch is available. As a temporary workaround, restrict the parsing of fonts from untrusted sources to minimize the risk of exploitation.
Exploit
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Office Publisher