Kingsoft Writer 2012 WPS file Buffer Overflow Vulnerability
Last Update Date:
19 Aug 2013 09:39
Release Date:
19 Aug 2013
4146
Views
RISK: High Risk
TYPE: Clients - Productivity Products
A vulnerability has been identified in Kingsoft Writer 2012, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to a boundary error in when handling font names and can be exploited to cause a stack-based buffer overflow via a specially crafted WPS file with an overly long font name.
Impact
- Remote Code Execution
System / Technologies affected
- Kingsoft Office 2012
- Kingsoft Writer 2012 8.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to Kingsoft Office 2013 version 9.1.0.4256.
Vulnerability Identifier
Source
Related Link
Share with