First published: Thu Dec 16 2010(Updated: )
pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 does not properly perform array indexing, which allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Array Indexing Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Publisher | =2002-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3955 has a severity rating that indicates it can lead to remote code execution due to memory corruption issues.
To fix CVE-2010-3955, it is recommended to apply the latest security updates provided by Microsoft for Publisher 2002 SP3.
CVE-2010-3955 can allow remote attackers to execute arbitrary code by exploiting vulnerabilities in crafted Publisher files.
CVE-2010-3955 specifically affects Microsoft Publisher 2002 SP3.
The risks associated with CVE-2010-3955 include potential unauthorized access to system resources and execution of malicious code.