CVE-2013-1316: Input Validation
Published May 15, 2013
·Updated
Microsoft Publisher 2003 SP3 does not properly validate the size of an unspecified array, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Negative Value Allocation Vulnerability."
Affected Software
1 affected component
Microsoft Publisher=2003-sp3
Event History
May 15, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1316?
CVE-2013-1316 is rated as critical due to its potential to allow remote code execution.
2
How do I fix CVE-2013-1316?
To fix CVE-2013-1316, apply the security updates provided by Microsoft for Microsoft Publisher 2003 SP3.
3
What products are affected by CVE-2013-1316?
CVE-2013-1316 affects Microsoft Publisher version 2003 SP3.
4
What kind of attacks can exploit CVE-2013-1316?
CVE-2013-1316 can be exploited by attackers using crafted Publisher files to execute arbitrary code.
5
Is there a workaround for CVE-2013-1316?
There are no official workarounds for CVE-2013-1316; the best mitigation is to apply the available updates.