PT-2007-4924 · Quark · Quarkxpress

Published

2007-07-11

·

Updated

2017-07-29

·

CVE-2007-3678

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions QuarkXPress version 7.2
Description A stack-based buffer overflow issue exists in the MSWord text-import extension of QuarkXPress, specifically when using the Rectangle Text Box tool for importing text. This allows remote attackers to execute arbitrary code via a long font name, but it requires user assistance.
Recommendations For QuarkXPress version 7.2, update to a newer version that addresses this issue to prevent exploitation. As a temporary workaround, consider avoiding the use of long font names when importing text with the Rectangle Text Box tool.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-3678

Affected Products

Quarkxpress