Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-13544

Опубликовано: 06 янв. 2021
Источник: nvd
CVSS3: 8.8
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

An exploitable sign extension vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker application. A specially crafted document can cause the document parser to sign-extend a length used to terminate a loop, which can later result in the loop’s index being used to write outside the bounds of a heap buffer during the reading of file data. An attacker can entice the victim to open a document to trigger this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:softmaker:softmaker_office:2021:*:*:*:*:*:*:*

EPSS

Процентиль: 47%
0.00243
Низкий

8.8 High

CVSS3

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-194
CWE-681

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

An exploitable sign extension vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker application. A specially crafted document can cause the document parser to sign-extend a length used to terminate a loop, which can later result in the loop’s index being used to write outside the bounds of a heap buffer during the reading of file data. An attacker can entice the victim to open a document to trigger this vulnerability.

EPSS

Процентиль: 47%
0.00243
Низкий

8.8 High

CVSS3

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-194
CWE-681