CVE-2013-6836
published 2013-12-19CVE-2013-6836: Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.75%
75.4th percentile
Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnumeric | < gnumeric 1.12.9-1 (bookworm) | gnumeric 1.12.9-1 (bookworm) |
| gnome | gnumeric | <= 1.12.8 | — |
| gnome | gnumeric | — | — |
| gnome | gnumeric | — | — |
| gnome | gnumeric | — | — |
| gnome | gnumeric | — | — |
| gnome | gnumeric | — | — |
| gnome | gnumeric | — | — |
| gnome | gnumeric | — | — |
| gnome | gnumeric | — | — |
| gnome | gnumeric | >= 0 < 1.12.9-1 | 1.12.9-1 |
| gnome | gnumeric | >= 0 < 1.12.9-1 | 1.12.9-1 |
| gnome | gnumeric | >= 0 < 1.12.9-1 | 1.12.9-1 |
| gnome | gnumeric | >= 0 < 1.12.9-1 | 1.12.9-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2252-2x7m-w7r8: Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher
ghsa_unreviewed·2022-05-17
CVE-2013-6836 [MEDIUM] CWE-119 GHSA-2252-2x7m-w7r8: Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher
Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.
OSV
CVE-2013-6836: Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher
osv·2013-12-19·CVSS 4.3
CVE-2013-6836 [MEDIUM] CVE-2013-6836: Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher
Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.
Debian
CVE-2013-6836: gnumeric - Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/m...
vendor_debian·2013·CVSS 4.3
CVE-2013-6836 [MEDIUM] CVE-2013-6836: gnumeric - Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/m...
Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.
Scope: local
bookworm: resolved (fixed in 1.12.9-1)
bullseye: resolved (fixed in 1.12.9-1)
forky: resolved (fixed in 1.12.9-1)
sid: resolved (fixed in 1.12.9-1)
trixie: resolved (fixed in 1.12.9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6836 gnumeric: heap-based buffer overflow in ms_escher_get_data function
bugzilla·2013-12-19·CVSS 4.3
CVE-2013-6836 [MEDIUM] CVE-2013-6836 gnumeric: heap-based buffer overflow in ms_escher_get_data function
CVE-2013-6836 gnumeric: heap-based buffer overflow in ms_escher_get_data function
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-6836 to the following vulnerability:
Name: CVE-2013-6836
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6836
Assigned: 20131120
Reference: https://bugzilla.gnome.org/show_bug.cgi?id=712772
Reference: https://git.gnome.org/browse/gnumeric/commit/?id=b5480b69345b3c6d56ee0ed9c9e9880bb2a08cdc
Reference: https://projects.gnome.org/gnumeric/announcements/1.12/gnumeric-1.12.9.shtml
Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.
Discussion
Bugzilla
CVE-2013-6836 gnumeric: heap-based buffer overflow in ms_escher_get_data function [epel-all]
bugzilla·2013-12-19·CVSS 4.3
CVE-2013-6836 [MEDIUM] CVE-2013-6836 gnumeric: heap-based buffer overflow in ms_escher_get_data function [epel-all]
CVE-2013-6836 gnumeric: heap-based buffer overflow in ms_escher_get_data function [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please
Bugzilla
CVE-2013-6836 gnumeric: heap-based buffer overflow in ms_escher_get_data function [fedora-all]
bugzilla·2013-12-19·CVSS 4.3
CVE-2013-6836 [MEDIUM] CVE-2013-6836 gnumeric: heap-based buffer overflow in ms_escher_get_data function [fedora-all]
CVE-2013-6836 gnumeric: heap-based buffer overflow in ms_escher_get_data function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please not
http://lists.opensuse.org/opensuse-updates/2014-02/msg00018.htmlhttp://secunia.com/advisories/56678http://www.securityfocus.com/bid/64459https://bugzilla.gnome.org/show_bug.cgi?id=712772https://git.gnome.org/browse/gnumeric/commit/?id=b5480b69345b3c6d56ee0ed9c9e9880bb2a08cdchttps://projects.gnome.org/gnumeric/announcements/1.12/gnumeric-1.12.9.shtmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00018.htmlhttp://secunia.com/advisories/56678http://www.securityfocus.com/bid/64459https://bugzilla.gnome.org/show_bug.cgi?id=712772https://git.gnome.org/browse/gnumeric/commit/?id=b5480b69345b3c6d56ee0ed9c9e9880bb2a08cdchttps://projects.gnome.org/gnumeric/announcements/1.12/gnumeric-1.12.9.shtml
2013-12-19
Published