CVE Published: 01/10/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2018 Source: talos |
Vendor: The Atlantis Word Processor Team |
Product: Atlantis Word Processor Status : PUBLISHED
CVE-2018-3975 Description
An exploitable uninitialized variable vulnerability exists in the RTF-parsing functionality of Atlantis Word Processor 3.2.6 version. A specially crafted RTF file can leverage an uninitialized stack address, resulting in an out-of-bounds write, which in turn could lead to code execution.