PT-2013-4751 · Kingsoft · Kingsoft Writer+1

Published

2013-09-10

·

Updated

2013-09-10

·

CVE-2013-3934

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Kingsoft Writer 2012 version 8.1.0.3030 Kingsoft Office 2013 versions prior to 9.1.0.4256
Description The issue is a stack-based buffer overflow that allows remote attackers to execute arbitrary code. This is achieved by using a long font name in a WPS file.
Recommendations For Kingsoft Writer 2012 version 8.1.0.3030, update to a newer version to mitigate the risk. For Kingsoft Office 2013 versions prior to 9.1.0.4256, update to version 9.1.0.4256 or later.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3934

Affected Products

Kingsoft Office
Kingsoft Writer