PT-2019-10739 · Atlantis · Atlantis Word Processor

CVE-2018-3983

·

Publicado

2019-10-31

·

Atualizado

2023-02-04

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Atlantis Word Processor (affected versions not specified)
Description The issue concerns an uninitialized pointer vulnerability in the Word document parser. It can be triggered by a specially crafted document, causing an array fetch to return an uninitialized pointer. This pointer is then used in arithmetic operations before writing a value to the result, potentially allowing an attacker to corrupt heap memory and execute code under the context of the application. The attacker must convince the victim to open the malicious document to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Access of Uninitialized Pointer

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-3983

Produtos afetados

Atlantis Word Processor