|
|
| |
|
| |
catdoc: denial of service
| Package(s): | catdoc |
CVE #(s): | |
| Created: | November 13, 2012 |
Updated: | November 21, 2012 |
| Description: |
From the Red Hat bugzilla:
A Debian bug report noted that there is a buffer overflow in catdoc's src/xlsparse.c, which contains:
for (i=0;i<NUMOFDATEFORMATS; i++);
FormatIdxUsed[i]=0;
Because of the ";" at the end of the first line, it effectively sets i to NUMOFDATEFORMATS, which will cause it to write past defined buffer. This could lead to a denial of service (crash of catdoc). The Debian bug report indicates that this could possibly be used for worse things than a crash, but I'm not sure (I can see it writing past the end of the buffer, but all it is writing is 0's and not anything user-defined).
|
| Alerts: |
|
( Log in to post comments)
|
|
|