Skip to main content

Kingsoft Writer 2012 WPS file Buffer Overflow Vulnerability

Last Update Date: 19 Aug 2013 09:39 Release Date: 19 Aug 2013 3381 Views

RISK: High Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

A vulnerability has been identified in Kingsoft Writer 2012, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a boundary error in when handling font names and can be exploited to cause a stack-based buffer overflow via a specially crafted WPS file with an overly long font name.


Impact

  • Remote Code Execution

System / Technologies affected

  • Kingsoft Office 2012
  • Kingsoft Writer 2012 8.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to Kingsoft Office 2013 version 9.1.0.4256.

Vulnerability Identifier


Source


Related Link