CVE-2020-25291: High severity wps office vulnerability
Published Sep 13, 2020
·Updated
GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Word document. This is related to QBrush::setMatrix in gui/painting/qbrush.cpp in Qt 4.x.
Affected Software
1 affected component
Kingsoft WPS Office<11.2.0.9403
Event History
Sep 13, 2020
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-25291.
2
What is the severity of CVE-2020-25291?
The severity of CVE-2020-25291 is high, with a severity value of 7.8.
3
What software is affected by CVE-2020-25291?
Kingsoft WPS Office versions up to 11.2.0.9403 are affected by CVE-2020-25291.
4
How does CVE-2020-25291 work?
CVE-2020-25291 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Word document.
5
Is there a fix available for CVE-2020-25291?
There is no specific fix mentioned in the provided information. It is recommended to update to the latest version of Kingsoft WPS Office to mitigate the vulnerability.