Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow...
Vulnerability Description
Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (1) JPG image to the ImportGR in the JPG image filter module (HncJpeg10.flt) or (2) PNG image to the PNG image filter module (HncPng10.flt), which triggers a heap-based buffer overflow.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-1206
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73026
- http://www.hancom.co.kr/notice.noticeView.do?targetRow=1¬ice_seqno=100
- http://secunia.com/advisories/47386
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73025
- http://osvdb.org/78906
- http://www.securityfocus.com/bid/51892
- http://osvdb.org/78907
More from hancom
View All →Affected Vendor
hancom
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.