PT-2018-16354 · Atlantis · Atlantis Word Processor
Published
2018-10-01
·
Updated
2022-04-19
·
CVE-2018-3978
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Atlantis Word Processor versions 3.0.2.3 through 3.0.2.5
Description
The issue is related to an out-of-bounds write in the Word Document parser. A specially crafted document can cause the software to write a value outside the bounds of a heap allocation, resulting in a buffer overflow. To trigger this, an attacker must convince a victim to open a malicious document.
Recommendations
For versions 3.0.2.3 through 3.0.2.5, avoid opening documents from untrusted sources until a patch is available. As a temporary workaround, consider restricting the use of the Word Document parser to minimize the risk of exploitation.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Atlantis Word Processor