Microsoft Publisher pubconv.dll cb Value Memory Corruption

Strike ID:
E10-10301
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1
Year:
2010

Description

This strike illustrates a vulnerability that exists in Microsoft Publisher documents. If the chpRun PapRun and tapRun records contain a tyo structure of 0x1D and its cb value is more than 2, data will be copied and overwrite memory on the stack buffer. This happens because the cb value is the size of a memmove operation that changes an argument pointer on the stack buffer.

CVE

Bid