Vulnerabilities > CVE-2012-1206 - Numeric Errors vulnerability in Hancom Office 2010 SE 8.5.5

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
hancom
CWE-189
critical

Summary

Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (1) JPG image to the ImportGR in the JPG image filter module (HncJpeg10.flt) or (2) PNG image to the PNG image filter module (HncPng10.flt), which triggers a heap-based buffer overflow.

Vulnerable Configurations

Part Description Count
Application
Hancom
1

Common Weakness Enumeration (CWE)