Description
When processing a record type of 0x3c from a Workbook stream from an Excel file (.xls), JustSystems Ichitaro Office trusts that the size is greater than zero, subtracts one from the length, and uses this result as the size for a memcpy. This results in a heap-based buffer overflow and can lead to code execution under the context of the application.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-11933 | When processing a record type of 0x3c from a Workbook stream from an Excel file (.xls), JustSystems Ichitaro Office trusts that the size is greater than zero, subtracts one from the length, and uses this result as the size for a memcpy. This results in a heap-based buffer overflow and can lead to code execution under the context of the application. |
References
History
No history.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-08-05T14:02:07.698Z
Reserved: 2016-12-01T00:00:00.000Z
Link: CVE-2017-2790
No data.
Status : Deferred
Published: 2017-02-24T22:59:00.200
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-2790
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD