First published: Thu Jun 05 2014(Updated: )
The (1) QProGetNotebookWindowHandle and (2) Ordinal132 functions in QPW160.dll in Corel Quattro Pro X6 Standard Edition 16.0.0.388 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted QPW file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Corel Quattro Pro X6 | <=16.0.0.388 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4728 is classified as a denial of service vulnerability, which can cause the application to crash.
To mitigate CVE-2012-4728, users should update Corel Quattro Pro X6 to a version later than 16.0.0.388.
CVE-2012-4728 affects Corel Quattro Pro X6 Standard Edition version 16.0.0.388 and earlier.
Attackers can exploit CVE-2012-4728 by sending crafted QPW files that trigger a NULL pointer dereference.
The impact of CVE-2012-4728 on users is the potential for application crashes, leading to denial of service.