First published: Tue Sep 10 2013(Updated: )
Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers to execute arbitrary code via a long font name in a WPS file.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kingsoft Office 2012 | =8.1.0.3385 | |
Kingsoft Writer 2012 | =8.1.0.3030 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3934 is classified as a high severity vulnerability due to its potential for remote code execution.
To mitigate CVE-2013-3934, update Kingsoft Office to version 9.1.0.4256 or later.
CVE-2013-3934 affects Kingsoft Writer 2012 version 8.1.0.3030 and Kingsoft Office 2013 prior to version 9.1.0.4256.
CVE-2013-3934 allows remote attackers to execute arbitrary code through crafted WPS files.
While CVE-2013-3934 is primarily a concern for outdated versions of Kingsoft products, any unpatched software may still be vulnerable.