R 3.4.4 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by injecting malicious input into the GUI Preferences language field. Attackers can craft a payload with a 292-byte offset and JMP ESP instruction to execute commands like calc.exe when the payload is pasted into the Language for menus and messages field.
{
"binaries": [
{
"binary_version": "3.4.4-1ubuntu1",
"binary_name": "r-base"
},
{
"binary_version": "3.4.4-1ubuntu1",
"binary_name": "r-base-core"
},
{
"binary_version": "3.4.4-1ubuntu1",
"binary_name": "r-base-dev"
},
{
"binary_version": "3.4.4-1ubuntu1",
"binary_name": "r-base-html"
},
{
"binary_version": "3.4.4-1ubuntu1",
"binary_name": "r-doc-html"
},
{
"binary_version": "3.4.4-1ubuntu1",
"binary_name": "r-doc-info"
},
{
"binary_version": "3.4.4-1ubuntu1",
"binary_name": "r-doc-pdf"
},
{
"binary_version": "3.4.4-1ubuntu1",
"binary_name": "r-mathlib"
},
{
"binary_version": "3.4.4-1ubuntu1",
"binary_name": "r-recommended"
}
]
}{
"binaries": [
{
"binary_version": "3.6.3-2",
"binary_name": "r-base"
},
{
"binary_version": "3.6.3-2",
"binary_name": "r-base-core"
},
{
"binary_version": "3.6.3-2",
"binary_name": "r-base-dev"
},
{
"binary_version": "3.6.3-2",
"binary_name": "r-base-html"
},
{
"binary_version": "3.6.3-2",
"binary_name": "r-doc-html"
},
{
"binary_version": "3.6.3-2",
"binary_name": "r-doc-info"
},
{
"binary_version": "3.6.3-2",
"binary_name": "r-doc-pdf"
},
{
"binary_version": "3.6.3-2",
"binary_name": "r-mathlib"
},
{
"binary_version": "3.6.3-2",
"binary_name": "r-recommended"
}
]
}{
"binaries": [
{
"binary_version": "4.1.2-1ubuntu2",
"binary_name": "r-base"
},
{
"binary_version": "4.1.2-1ubuntu2",
"binary_name": "r-base-core"
},
{
"binary_version": "4.1.2-1ubuntu2",
"binary_name": "r-base-dev"
},
{
"binary_version": "4.1.2-1ubuntu2",
"binary_name": "r-base-html"
},
{
"binary_version": "4.1.2-1ubuntu2",
"binary_name": "r-doc-html"
},
{
"binary_version": "4.1.2-1ubuntu2",
"binary_name": "r-doc-info"
},
{
"binary_version": "4.1.2-1ubuntu2",
"binary_name": "r-doc-pdf"
},
{
"binary_version": "4.1.2-1ubuntu2",
"binary_name": "r-mathlib"
},
{
"binary_version": "4.1.2-1ubuntu2",
"binary_name": "r-recommended"
}
]
}{
"binaries": [
{
"binary_version": "4.3.3-2build2",
"binary_name": "r-base"
},
{
"binary_version": "4.3.3-2build2",
"binary_name": "r-base-core"
},
{
"binary_version": "4.3.3-2build2",
"binary_name": "r-base-dev"
},
{
"binary_version": "4.3.3-2build2",
"binary_name": "r-base-html"
},
{
"binary_version": "4.3.3-2build2",
"binary_name": "r-doc-html"
},
{
"binary_version": "4.3.3-2build2",
"binary_name": "r-doc-info"
},
{
"binary_version": "4.3.3-2build2",
"binary_name": "r-doc-pdf"
},
{
"binary_version": "4.3.3-2build2",
"binary_name": "r-mathlib"
},
{
"binary_version": "4.3.3-2build2",
"binary_name": "r-recommended"
}
]
}{
"binaries": [
{
"binary_version": "4.5.1-1",
"binary_name": "r-base"
},
{
"binary_version": "4.5.1-1",
"binary_name": "r-base-core"
},
{
"binary_version": "4.5.1-1",
"binary_name": "r-base-dev"
},
{
"binary_version": "4.5.1-1",
"binary_name": "r-base-html"
},
{
"binary_version": "4.5.1-1",
"binary_name": "r-doc-html"
},
{
"binary_version": "4.5.1-1",
"binary_name": "r-doc-info"
},
{
"binary_version": "4.5.1-1",
"binary_name": "r-doc-pdf"
},
{
"binary_version": "4.5.1-1",
"binary_name": "r-mathlib"
},
{
"binary_version": "4.5.1-1",
"binary_name": "r-recommended"
}
]
}{
"binaries": [
{
"binary_version": "3.0.2-1ubuntu1.1~esm2",
"binary_name": "r-base"
},
{
"binary_version": "3.0.2-1ubuntu1.1~esm2",
"binary_name": "r-base-core"
},
{
"binary_version": "3.0.2-1ubuntu1.1~esm2",
"binary_name": "r-base-dev"
},
{
"binary_version": "3.0.2-1ubuntu1.1~esm2",
"binary_name": "r-base-html"
},
{
"binary_version": "3.0.2-1ubuntu1.1~esm2",
"binary_name": "r-doc-html"
},
{
"binary_version": "3.0.2-1ubuntu1.1~esm2",
"binary_name": "r-doc-info"
},
{
"binary_version": "3.0.2-1ubuntu1.1~esm2",
"binary_name": "r-doc-pdf"
},
{
"binary_version": "3.0.2-1ubuntu1.1~esm2",
"binary_name": "r-mathlib"
},
{
"binary_version": "3.0.2-1ubuntu1.1~esm2",
"binary_name": "r-recommended"
}
]
}{
"binaries": [
{
"binary_version": "3.2.3-4ubuntu0.1~esm3",
"binary_name": "r-base"
},
{
"binary_version": "3.2.3-4ubuntu0.1~esm3",
"binary_name": "r-base-core"
},
{
"binary_version": "3.2.3-4ubuntu0.1~esm3",
"binary_name": "r-base-dev"
},
{
"binary_version": "3.2.3-4ubuntu0.1~esm3",
"binary_name": "r-base-html"
},
{
"binary_version": "3.2.3-4ubuntu0.1~esm3",
"binary_name": "r-doc-html"
},
{
"binary_version": "3.2.3-4ubuntu0.1~esm3",
"binary_name": "r-doc-info"
},
{
"binary_version": "3.2.3-4ubuntu0.1~esm3",
"binary_name": "r-doc-pdf"
},
{
"binary_version": "3.2.3-4ubuntu0.1~esm3",
"binary_name": "r-mathlib"
},
{
"binary_version": "3.2.3-4ubuntu0.1~esm3",
"binary_name": "r-recommended"
}
]
}