First published: Thu Dec 16 2010(Updated: )
Array index error in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher 97 file, aka "Memory Corruption Due To Invalid Index Into Array in Pubconv.dll Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Publisher 2010 | =2002-sp3 | |
Microsoft Publisher 2010 | =2003-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2571 has been assigned a high severity rating due to its potential to allow remote code execution.
To fix CVE-2010-2571, you should apply the latest security updates provided by Microsoft for Microsoft Publisher 2002 and 2003.
CVE-2010-2571 affects Microsoft Publisher 2002 SP3 and Microsoft Publisher 2003 SP3.
Yes, CVE-2010-2571 can be exploited through user interaction by opening a specially crafted Publisher 97 file.
CVE-2010-2571 is an array index error vulnerability that can lead to memory corruption and allows execution of arbitrary code.