CVE-2022-39843
Published on: Not Yet Published
Last Modified on: 09/09/2022 02:45:00 PM UTC
Certain versions of Linux Kernel from Linux contain the following vulnerability:
123elf Lotus 1-2-3 before 1.0.0rc3 for Linux, and Lotus 1-2-3 R3 for UNIX and other platforms through 9.8.2, allow attackers to execute arbitrary code via a crafted worksheet. This occurs because of a stack-based buffer overflow in the cell format processing routines, as demonstrated by a certain function call from process_fmt() that can be reached via a w3r_format element in a wk3 document.
- CVE-2022-39843 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Exploitable Stack Overflow · Issue #103 · taviso/123elf · GitHub | github.com text/html |
![]() |
Release New Release · taviso/123elf · GitHub | github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Linux | Linux Kernel | - | All | All | All |
Application | Lotus 1-2-3 Project | Lotus 1-2-3 | 1.0.0 | rc1 | All | All |
Application | Lotus 1-2-3 Project | Lotus 1-2-3 | 1.0.0 | rc2 | All | All |
- cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*:
- cpe:2.3:a:lotus_1-2-3_project:lotus_1-2-3:1.0.0:rc1:*:*:*:*:*:*:
- cpe:2.3:a:lotus_1-2-3_project:lotus_1-2-3:1.0.0:rc2:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-39843 : 123elf Lotus 1-2-3 before 1.0.0rc3 for #Linux, and Lotus 1-2-3 R3 for UNIX and other platforms thr… twitter.com/i/web/status/1… | 2022-09-05 07:04:57 |
![]() |
Potentially Critical CVE Detected! CVE-2022-39843 123elf Lotus 1-2-3 before 1.0.0rc3 for Linux, and Lotus 1-2-3 R3… twitter.com/i/web/status/1… | 2022-09-05 07:55:59 |
![]() |
New Vulnerability: CVE-2022-39843 #InceptusSecure #UnderOurProtection | 2022-09-05 10:16:23 |
![]() |
Ein cve ganz nach meinem Geschmack von der Produktseite her | 2022-09-05 10:35:51 |
![]() |
CVE-2022-39843 Published Date: 2022-09-05 [corrected for proper ISO date] 123elf Lotus 1-2-3 before 1.0.0rc3 for… twitter.com/i/web/status/1… | 2022-09-05 10:39:05 |
![]() |
CVE-2022-39843 | 2022-09-05 07:39:02 |