PT-2012-3129 · Hancom · Hancom Office 2010 Se

Published

2012-02-20

·

Updated

2017-08-29

·

CVE-2012-1206

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Hancom Office 2010 SE version 8.5.5
Description The issue is related to multiple integer overflows that can be triggered by large dimension values in JPG or PNG images. This can lead to a heap-based buffer overflow, allowing remote attackers to execute arbitrary code. The vulnerability can be exploited through the ImportGR in the JPG image filter module (HncJpeg10.flt) or the PNG image filter module (HncPng10.flt).
Recommendations For Hancom Office 2010 SE version 8.5.5, consider disabling the HncJpeg10.flt and HncPng10.flt modules to prevent the exploitation of this issue until a patch is available. Avoid opening or importing JPG and PNG images from untrusted sources to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1206

Affected Products

Hancom Office 2010 Se