PT-2014-2284 · Corel · Corel Quattro Pro X6

Published

2014-06-05

·

Updated

2017-08-29

·

CVE-2012-4728

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Corel Quattro Pro X6 Standard Edition versions 16.0.0.388 and earlier
Description The issue allows remote attackers to cause a denial of service, resulting in a crash due to a NULL pointer dereference, by providing a crafted QPW file. This is related to the QProGetNotebookWindowHandle and Ordinal132 functions in QPW160.dll.
Recommendations For versions 16.0.0.388 and earlier, consider avoiding the use of crafted QPW files until a fix is available. As a temporary workaround, restrict the opening of QPW files from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2012-4728

Affected Products

Corel Quattro Pro X6