First published: Mon Jan 29 2018(Updated: )
The WStr::assign function in kso.dll in Kingsoft WPS Office 10.1.0.7106 and 10.2.0.5978 does not validate the size of the source memory block before an _copy call, which allows remote attackers to cause a denial of service (access violation and application crash) via a crafted (a) web page, (b) office document, or (c) .rtf file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WPS Office | =10.1.0.7106 | |
WPS Office | =10.2.0.5978 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6390 has a severity rating that indicates it can cause a denial of service due to an access violation.
To fix CVE-2018-6390, users should update WPS Office to a version that addresses the vulnerability, specifically versions beyond 10.2.0.5978.
CVE-2018-6390 affects WPS Office versions 10.1.0.7106 and 10.2.0.5978.
CVE-2018-6390 enables remote attackers to cause denial of service attacks through crafted inputs.
Yes, CVE-2018-6390 is related to improper validation of memory block sizes before copying, leading to potential crashes.