CVE-2015-2810
Summary
| CVE | CVE-2015-2810 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-05-15 22:59:00 UTC |
| Updated | 2016-12-03 03:06:00 UTC |
| Description | Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWord Viewer 2007 and Viewer 2010 8.5.6.1158, and HwpViewer 2014 VP 9.1.0.2186, allows remote attackers to cause a denial of service (crash) and possibly "influence the program's execution flow" via a document with a large paragraph size, which triggers heap corruption. |
Risk And Classification
Problem Types: CWE-189
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hancom | Hanword Viewer 2007 | All | All | All | All |
| Application | Hancom | Hanword Viewer 2007 | All | All | All | All |
| Application | Hancom | Hanword Viewer 2010 | 8.5.6.1158 | All | All | All |
| Application | Hancom | Hanword Viewer 2010 | 8.5.6.1158 | All | All | All |
| Application | Hancom | Hwpviewer 2014 | 9.1.0.2186 | All | All | All |
| Application | Hancom | Hwpviewer 2014 | 9.1.0.2186 | All | All | All |
| Application | Hancom | Hwp 2014 | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Malformed Request | BID | www.securityfocus.com | |
| Bugtraq: [CVE-2015-2810] Integer Overflow leading to heap corruption when assigning a long paragraph size value to a HanWord document | BUGTRAQ | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.