CVE-2013-6836: Buffer Overflow
Published Dec 19, 2013
·Updated
Heap-based buffer overflow in the mseschergetdata function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.
Affected Software
9 affected components
Gnome Gnumeric<=1.12.8
Gnome Gnumeric=1.12.0
Gnome Gnumeric=1.12.1
Gnome Gnumeric=1.12.2
Gnome Gnumeric=1.12.3
Gnome Gnumeric=1.12.4
Gnome Gnumeric=1.12.5
Gnome Gnumeric=1.12.6
Gnome Gnumeric=1.12.7
Remediation
Event History
Dec 19, 2013
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·04:24 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6836?
CVE-2013-6836 has a medium severity rating due to its potential to cause a denial of service.
2
How do I fix CVE-2013-6836?
To fix CVE-2013-6836, upgrade Gnumeric to version 1.12.9 or later.
3
What versions of Gnumeric are affected by CVE-2013-6836?
CVE-2013-6836 affects Gnumeric versions prior to 1.12.9, including 1.12.0 through 1.12.8.
4
What type of vulnerability is CVE-2013-6836?
CVE-2013-6836 is a heap-based buffer overflow vulnerability.
5
Can CVE-2013-6836 be exploited remotely?
Yes, CVE-2013-6836 can be exploited remotely through a crafted xls file.