CVE-2007-1754
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical pointers to NULL, aka the "Publisher Invalid Memory Reference Vulnerability".
La biblioteca PUBCONV.DLL en Microsoft Office Publisher 2007 no borra apropiadamente la memoria al transferir datos del disco a la memoria, lo que permite a los atacantes remotos asistidos por el usuario ejecutar código arbitrario por medio de una página .pub malformada mediante un valor negativo determinado, que omite un procedimiento de saneamiento que inicializa punteros críticos a NULL, también se conoce como la "Publisher Invalid Memory Reference Vulnerability”.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-03-29 CVE Reserved
- 2007-07-10 CVE Published
- 2024-05-13 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://osvdb.org/35953 | Vdb Entry | |
http://research.eeye.com/html/advisories/published/AD20070710.html | X_refsource_misc | |
http://www.securityfocus.com/archive/1/473309/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1018353 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA07-191A.html | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1871 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html | 2018-10-16 | |
http://secunia.com/advisories/25988 | 2018-10-16 | |
http://www.vupen.com/english/advisories/2007/2479 | 2018-10-16 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-037 | 2018-10-16 |