vendor:
R
by:
ZwX
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: R
Affected Version From: 3.4.2004
Affected Version To: 3.4.2004
Patch Exists: NO
Related CWE:
CPE: a:r-project:r:3.4.4
Platforms Tested: Windows 7
2018
R v3.4.4 – (SEH) Buffer Overflow Exploit
A local buffer overflow vulnerability has been discovered in the official R v3.4.4 software. The vulnerability allows local attackers to overwrite the registers (example eip) to compromise the local software process. The issue can be exploited by local attackers with system privileges to compromise the affected local computer system. The vulnerability is marked as classic buffer overflow issue.
Mitigation:
Apply the latest patch or upgrade to a newer version of R.