CVE-2022-39843

Source
https://cve.org/CVERecord?id=CVE-2022-39843
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-39843.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-39843
Published
2022-09-05T07:15:08.207Z
Modified
2025-11-14T13:37:40.356753Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

123elf Lotus 1-2-3 before 1.0.0rc3 for Linux, and Lotus 1-2-3 R3 for UNIX and other platforms through 9.8.2, allow attackers to execute arbitrary code via a crafted worksheet. This occurs because of a stack-based buffer overflow in the cell format processing routines, as demonstrated by a certain function call from processfmt() that can be reached via a w3rformat element in a wk3 document.

References

Affected packages

Git / github.com/taviso/123elf

Affected ranges

Type
GIT
Repo
https://github.com/taviso/123elf
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*

v1.0.0-rc1
v1.0.0rc2

Database specific

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-39843.json"