Lucene search

K
cve[email protected]CVE-2008-2152
HistoryJun 10, 2008 - 6:32 p.m.

CVE-2008-2152

2008-06-1018:32:00
CWE-189
web.nvd.nist.gov
34
cve-2008-2152
integer overflow
rtl_allocatememory
openoffice.org
remote code execution
buffer overflow
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

High

0.087 Low

EPSS

Percentile

94.6%

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.

Affected configurations

NVD
Node
openofficeopenoffice.orgMatch2.0
OR
openofficeopenoffice.orgMatch2.1
OR
openofficeopenoffice.orgMatch2.2
OR
openofficeopenoffice.orgMatch2.3
OR
openofficeopenoffice.orgMatch2.4

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

High

0.087 Low

EPSS

Percentile

94.6%