vendor:
R
by:
Dino Covotsos
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: R
Affected Version From: 3.4.2004
Affected Version To: 3.4.2004
Patch Exists: NO
Related CWE: TBC
CPE: a:r-project:r:3.4.4
Platforms Tested: Windows XP Prof SP3 ENG x86
2019
R 3.4.4 – Local Buffer Overflow (Windows XP SP3)
This exploit allows a local buffer overflow in R version 3.4.4 on Windows XP SP3. The exploit author, Dino Covotsos from Telspace Systems, has generated a proof-of-concept (PoC) that demonstrates the vulnerability. The exploit does not require SEH exploitation and has been tested on Windows XP Prof SP3 ENG x86.
Mitigation:
Apply the latest patch or upgrade to a non-vulnerable version of the software.