Remote Code Execution via Crafted Microsoft Word Document in Antenna House Office Server Document Converter

Remote Code Execution via Crafted Microsoft Word Document in Antenna House Office Server Document Converter

CVE-2018-3931 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft Word (DOC) document can lead to an out-of-bounds write, resulting in remote code execution. This vulnerability occurs in the `putShapeProperty` method.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.