PT-2017-8463 · Hancom · Hancom Office
Published
2017-01-06
·
Updated
2017-01-11
·
CVE-2016-4296
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hancom Office 2014
Description
The issue occurs when opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object. The application searches for an underscore (" ") character at the end of the string and writes a null terminator after it. If the character is at the very end of the string, the application mistakenly writes the null-byte outside the bounds of its destination, resulting in heap corruption. This can lead to code execution under the context of the application.
Recommendations
For Hancom Office 2014, avoid opening Hangul Hcell Documents (.cell) that may trigger the vulnerability until a patch is available. As a temporary workaround, consider restricting the use of the CSSValFormat object in Hangul Hcell Documents to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hancom Office