Skip to content

123ADV-001: Stack Buffer Overflow in Lotus 1-2-3 R3 for UNIX/Linux

High
taviso published GHSA-mchg-c39f-96pj Sep 5, 2022

Package

lotus123r3 (N/A)

Affected versions

< 1.0.0rc3

Patched versions

1.0.0rc3

Description

About

The 123 command is a spreadsheet application for UNIX-based systems that can be used in interactive mode to create and modify financial and scientific models.

For more information, see https://123r3.net

Advisory

A stack buffer overflow was reported in the cell format processing routines. If a victim opens an untrusted malicious worksheet, code execution could occur.

There have been no reports of this vulnerability being exploited in the wild.

We take your security very seriously, in fact, this is the first known vulnerability reported in Lotus 1-2-3 R3 since it's release in September 1990.

Credit

This issue was reported to the 123elf project by dbastone.

Solution

A new release has been prepared to resolve this issue, we recommend affected users upgrade immediately.

https://github.com/taviso/123elf/

Lotus 1-2-3 releases for other platforms are affected, but are not actively maintained. MS-DOS, OS/2, OpenVMS, z/OS and SysV/386 users are advised to migrate to Linux to continue receiving updates.

Severity

High

CVE ID

CVE-2022-39843

Weaknesses

Credits