PT-2014-2284 · Corel · Corel Quattro Pro X6
Published
2014-06-05
·
Updated
2017-08-29
·
CVE-2012-4728
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Corel Quattro Pro X6 Standard Edition versions 16.0.0.388 and earlier
Description
The issue allows remote attackers to cause a denial of service, resulting in a crash due to a NULL pointer dereference, by providing a crafted QPW file. This is related to the QProGetNotebookWindowHandle and Ordinal132 functions in QPW160.dll.
Recommendations
For versions 16.0.0.388 and earlier, consider avoiding the use of crafted QPW files until a fix is available. As a temporary workaround, restrict the opening of QPW files from untrusted sources to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Corel Quattro Pro X6