Vulnerabilities > CVE-2022-39843 - Out-of-bounds Write vulnerability in Lotus 1-2-3 Project Lotus 1-2-3 1.0.0

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
lotus-1-2-3-project
CWE-787

Summary

123elf Lotus 1-2-3 before 1.0.0rc3 for Linux, and Lotus 1-2-3 R3 for UNIX and other platforms through 9.8.2, allow attackers to execute arbitrary code via a crafted worksheet. This occurs because of a stack-based buffer overflow in the cell format processing routines, as demonstrated by a certain function call from process_fmt() that can be reached via a w3r_format element in a wk3 document.

Vulnerable Configurations

Part Description Count
Application
Lotus_1-2-3_Project
2
OS
Linux
1

Common Weakness Enumeration (CWE)