vendor:
R
by:
bzyo
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: R
Affected Version From: 3.4.4
Affected Version To: 3.4.4
Patch Exists: YES
Related CWE: CVE-2018-9060
CPE: a:r_project:r:3.4.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 x86
2018
R 3.4.4 – Local Buffer Overflow
R 3.4.4 is vulnerable to a local buffer overflow vulnerability. An attacker can exploit this vulnerability by generating a malicious file, copying its contents to the clipboard, opening the application, selecting Edit, selecting 'GUI preferences', pasting the malicious file contents into 'Language for menus and messages', and selecting OK. This will cause a pop calc.
Mitigation:
Upgrade to the latest version of R 3.4.4