CVE-2018-3975
01.10.2018, 20:29
An exploitable uninitialized variable vulnerability exists in the RTF-parsing functionality of Atlantis Word Processor 3.2.6 version. A specially crafted RTF file can leverage an uninitialized stack address, resulting in an out-of-bounds write, which in turn could lead to code execution.Enginsight
Vendor | Product | Version |
---|---|---|
atlantiswordprocessor | atlantis_word_processor | 3.2.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration