CVE-2013-6836

GNOME Gnumeric < 1.12.9 - Heap-Based Buffer Overflow via Crafted XLS File

Title source: llm
STIX 2.1

Description

Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.

References (6)

Core 6
Core References
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2014-02/msg00018.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/64459
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56678

Scores

EPSS 0.0116
EPSS Percentile 78.8%

Details

CWE
CWE-119
Status published
Products (9)
gnome/gnumeric 1.12.0
gnome/gnumeric 1.12.1
gnome/gnumeric 1.12.2
gnome/gnumeric 1.12.3
gnome/gnumeric 1.12.4
gnome/gnumeric 1.12.5
gnome/gnumeric 1.12.6
gnome/gnumeric 1.12.7
gnome/gnumeric < 1.12.8
Published Dec 19, 2013
Tracked Since Feb 18, 2026