PT-2015-5905 · Hancom · Hwpviewer+2
Dan Caselden
+1
·
Published
2015-05-15
·
Updated
2016-12-03
·
CVE-2015-2810
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Hancom Office HanWord processor versions prior to 9.1.0.2342
HanWord Viewer 2007 and Viewer 2010 version 8.5.6.1158
HwpViewer 2014 VP version 9.1.0.2186
Description
The issue is related to an integer overflow in the HwpApp::CHncSDS Manager function. This can be triggered by a document with a large paragraph size, leading to heap corruption. As a result, remote attackers can cause a denial of service (crash) and possibly influence the program's execution flow.
Recommendations
For Hancom Office HanWord processor versions prior to 9.1.0.2342, update to version 9.1.0.2342 or later.
For HanWord Viewer 2007 and Viewer 2010 version 8.5.6.1158, update to a version later than 8.5.6.1158.
For HwpViewer 2014 VP version 9.1.0.2186, update to a version later than 9.1.0.2186.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hanword Viewer
Hancom Office Hanword
Hwpviewer