Heap-based buffer overflow in gnumeric - CVE-2013-6836
Published: December 19, 2013 / Updated: March 15, 2021
gnumeric
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9. A remote attacker can use a crafted xls file with a crafted length value. to trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
How to mitigate CVE-2013-6836
Sources
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00018.html
- http://secunia.com/advisories/56678
- http://www.securityfocus.com/bid/64459
- https://bugzilla.gnome.org/show_bug.cgi?id=712772
- https://git.gnome.org/browse/gnumeric/commit/?id=b5480b69345b3c6d56ee0ed9c9e9880bb2a08cdc
- https://projects.gnome.org/gnumeric/announcements/1.12/gnumeric-1.12.9.shtml