CVE-2007-6534: Input Validation
Published Dec 27, 2007
·Updated
Multiple unspecified vulnerabilities in Microsoft Office Publisher allow user-assisted remote attackers to cause a denial of service (application crash) via a crafted PUB file, possibly involving wordart.
Affected Software
5 affected components
Microsoft Publisher=2000
Microsoft Publisher=2002
Microsoft Publisher=2002-sp3
Microsoft Publisher=2003
Microsoft Publisher=2007
Event History
Dec 27, 2007
CVE Published
11:46 PM
Dec 28, 2007
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6534?
CVE-2007-6534 has been classified as a denial of service vulnerability, which can cause application crashes.
2
How do I fix CVE-2007-6534?
To fix CVE-2007-6534, users should apply any available security updates for their version of Microsoft Publisher.
3
What versions of Microsoft Publisher are affected by CVE-2007-6534?
CVE-2007-6534 affects Microsoft Publisher 2000, 2002, 2002 SP3, 2003, and 2007.
4
What type of attack does CVE-2007-6534 facilitate?
CVE-2007-6534 allows user-assisted remote attackers to trigger denial of service through specially crafted PUB files.
5
Is user input necessary to exploit CVE-2007-6534?
Yes, CVE-2007-6534 requires user interaction in order to exploit the vulnerability.