Unrated severityNVD Advisory· Published Sep 13, 2020· Updated Aug 4, 2024
CVE-2020-25291
CVE-2020-25291
Description
GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Word document. This is related to QBrush::setMatrix in gui/painting/qbrush.cpp in Qt 4.x.
Affected products
2- Kingsoft/WPS Officedescription
- Range: <11.2.0.9403
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- zeifan.my/security/rce/heap/2020/09/03/wps-rce-heap.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.