CVE-2020-25291

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
13/09/2020
Last modified:
17/09/2020

Description

GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Word document. This is related to QBrush::setMatrix in gui/painting/qbrush.cpp in Qt 4.x.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kingsoft:wps_office:*:*:*:*:*:*:*:* 11.2.0.9403 (excluding)


References to Advisories, Solutions, and Tools