#VU49296 Unexpected Sign Extension in TextMaker 2021 - CVE-2020-13544
Published: January 6, 2021
TextMaker 2021
SoftMaker
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to unexpected sign extension in the TextMaker document parsing functionality within record 0x001f. A remote attacker can trick a victim to open a specially crafted document and cause the document parser to sign-extend a length used to terminate a loop, resulting in the loop’s index being used to write outside the bounds of a heap buffer during the reading of file data.