HIGH · 9.3

CVE-2012-1206

Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (1) JPG image to the ImportGR in the JPG image filter module ...

Vulnerability Description

Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (1) JPG image to the ImportGR in the JPG image filter module (HncJpeg10.flt) or (2) PNG image to the PNG image filter module (HncPng10.flt), which triggers a heap-based buffer overflow.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
HancomHancom Office 2010 Se8.5.5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-1206?

CVE-2012-1206 is a vulnerability with a CVSS score of 9.3 (HIGH). Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (1) JPG image to the ImportGR in the JPG image filter module ...

How severe is CVE-2012-1206?

CVE-2012-1206 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-1206?

Check the references section above for vendor advisories and patch information. Affected products include: Hancom Hancom Office 2010 Se.