Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Office 2010 8.5.8.1724 and earlier versions have a heap overflow vulnerability when handling Compound File in document. This result in a program crash or denial of service conditions.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=30116 | third party advisory patch |