CVE

Id
25111  
CVE No.
CVE-2007-1754  
Status
Candidate  
Description
PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical pointers to NULL, aka the "Publisher Invalid Memory Reference Vulnerability".  
Phase
Assigned (20070329)  
Votes
None (candidate not yet proposed)  
Comments