Executive brief
R i386 is a popular open-source software environment used for statistical computing and graphics. A security flaw in version 3.5.0 allows a local user to take full control of the application by entering a specially crafted string into the language settings menu. This could lead to the execution of unauthorized commands or malicious software on the user's computer.
Technical details
A local buffer overflow vulnerability exists in R i386 version 3.5.0 within the 'Language for menus and messages' field of the GUI Preferences dialog. The issue is caused by an out-of-bounds write (CWE-787) when processing overly long input strings, which allows an attacker to overwrite the Structured Exception Handler (SEH) records. By crafting a specific payload, a local attacker can redirect execution flow to arbitrary shellcode. While the attack requires local access to the GUI, it does not require elevated privileges or specific user interaction beyond the input itself. Proof-of-concept exploits demonstrating code execution (e.g., launching a calculator) have been publicly disclosed.
Affected products
- R-Project R i386 3.5.0
Timeline
- 2019-01-30: disclosed: Initial discovery and PoC by Telspace Systems
- 2019-01-31: other: Exploit published on Exploit-DB
- 2026-04-05: advisory: CVE-2019-25656 published/assigned