Vulnerability Description
An exploitable heap-based buffer overflow exists in the Hangul Word Processor component (version 9.6.1.4350) of Hancom Thinkfree Office NEO 9.6.1.4902. A specially crafted document stream can cause an integer underflow resulting in a buffer overflow which can lead to code execution under the context of the application. An attacker can entice a user to open up a document in order to trigger this vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hancom | Hangul Word Processor | 9.6.1.4350 |
| Hancom | Thinkfree Office Neo | 9.6.1.4902 |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0320ExploitThird Party AdvisoryVDB Entry
- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0320ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2017-2819?
CVE-2017-2819 is a vulnerability with a CVSS score of 8.8 (HIGH). An exploitable heap-based buffer overflow exists in the Hangul Word Processor component (version 9.6.1.4350) of Hancom Thinkfree Office NEO 9.6.1.4902. A specially crafted document stream can cause an...
How severe is CVE-2017-2819?
CVE-2017-2819 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-2819?
Check the references section above for vendor advisories and patch information. Affected products include: Hancom Hangul Word Processor, Hancom Thinkfree Office Neo.