An out-of-bounds write (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. A size used by memmove is read from the input file. This is fixed in 6.9d.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://drive.google.com/open?id=175_n6KhbOUlu9l0ySw-8QYk0oQbAaoZV | third party advisory exploit |
http://www.dessci.com/en/dl/ | product vendor advisory |