CVE-2013-3934: Buffer Overflow
Published Sep 10, 2013
·Updated
Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers to execute arbitrary code via a long font name in a WPS file.
Affected Software
2 affected components
Kingsoft Office 2012=8.1.0.3385
Kingsoft Writer 2012=8.1.0.3030
Event History
Sep 10, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3934?
CVE-2013-3934 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2013-3934?
To mitigate CVE-2013-3934, update Kingsoft Office to version 9.1.0.4256 or later.
3
What versions are affected by CVE-2013-3934?
CVE-2013-3934 affects Kingsoft Writer 2012 version 8.1.0.3030 and Kingsoft Office 2013 prior to version 9.1.0.4256.
4
What type of attack does CVE-2013-3934 enable?
CVE-2013-3934 allows remote attackers to execute arbitrary code through crafted WPS files.
5
Is CVE-2013-3934 still a threat today?
While CVE-2013-3934 is primarily a concern for outdated versions of Kingsoft products, any unpatched software may still be vulnerable.