Release date:
Updated on:
Affected Systems:
PosterSoftware Publish-it 3.6d
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65366
CVE (CAN) ID: CVE-2014-0980
Publish-it is a Windows desktop publishing program.
Publish-it 3.6d and other versions have client errors when processing PUI files. Remote attackers can exploit this vulnerability to execute arbitrary code on the target system.
<* Source: Daniel Kazimirow
Link: http://secunia.com/advisories/56618
Http://www.exploit-db.com/exploits/31461/
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
For the POC provided by discovery CoreLabs, see the following link.
Http://www.coresecurity.com/system/files/attachments/2014/02/CORE-2014-0001-publish-it.zip
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PosterSoftware
--------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.postersw.com/publish.html