PT-2018-17691 · Design Science · Mathtype
Publicado
2018-02-28
·
Atualizado
2021-05-27
·
CVE-2018-6641
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Design Science MathType version 6.9c
Description
A Remote Code Execution issue was discovered, where crafted input can overwrite a structure, leading to a function call with an invalid parameter, and a subsequent free of important data.
Recommendations
For Design Science MathType version 6.9c, update to version 6.9d to resolve the issue.
Exploit
Correção
Use After Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mathtype