vendor:
R
by:
Dino Covotsos - Telspace Systems
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: R
Affected Version From: 3.5.2000
Affected Version To: 3.5.2000
Patch Exists: NO
Related CWE: TBC from Mitre
CPE: a:r-project:r:3.5.0
Platforms Tested: Windows XP Prof SP3 ENG x86
2019
R i386 3.5.0 – Local Buffer Overflow (SEH)
This exploit takes advantage of a local buffer overflow vulnerability in R i386 version 3.5.0. By pasting the exploit code in the 'Gui Preferences' section of the application, an attacker can execute arbitrary code, in this case opening the calculator. The exploit uses a SEH exploitation method and has been tested on Windows XP Prof SP3 ENG x86.
Mitigation:
Update to a version of R that is not vulnerable.