CVE-2010-2571: Input Validation
Array index error in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher 97 file, aka "Memory Corruption Due To Invalid Index Into Array in Pubconv.dll Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2571?
CVE-2010-2571 has been assigned a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2010-2571?
To fix CVE-2010-2571, you should apply the latest security updates provided by Microsoft for Microsoft Publisher 2002 and 2003.
What versions of Microsoft Publisher are affected by CVE-2010-2571?
CVE-2010-2571 affects Microsoft Publisher 2002 SP3 and Microsoft Publisher 2003 SP3.
Can CVE-2010-2571 be exploited through user interaction?
Yes, CVE-2010-2571 can be exploited through user interaction by opening a specially crafted Publisher 97 file.
What type of vulnerability is CVE-2010-2571?
CVE-2010-2571 is an array index error vulnerability that can lead to memory corruption and allows execution of arbitrary code.