CVE-2018-6641

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
28/02/2018
Last modified:
27/05/2021

Description

An Arbitrary Free (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can overwrite a structure, leading to a function call with an invalid parameter, and a subsequent free of important data such as a function pointer or list pointer. This is fixed in 6.9d.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wiris:mathtype:6.9c:*:*:*:*:*:*:*