Lucene search

K
cve[email protected]CVE-2012-2334
HistoryJun 19, 2012 - 8:55 p.m.

CVE-2012-2334

2012-06-1920:55:06
CWE-189
web.nvd.nist.gov
47
cve-2012-2334
openoffice.org
libreoffice
integer overflow
denial of service
buffer overflow
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

High

0.039 Low

EPSS

Percentile

92.0%

Integer overflow in filter/source/msfilter/msdffimp.cxx in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the length of an Escher graphics record in a PowerPoint (.ppt) document, which triggers a buffer overflow.

Affected configurations

NVD
Node
apacheopenoffice.orgMatch3.3
OR
apacheopenoffice.orgMatch3.4beta
Node
libreofficelibreofficeRange≀3.5.2
OR
libreofficelibreofficeMatch3.3.0
OR
libreofficelibreofficeMatch3.3.1
OR
libreofficelibreofficeMatch3.3.2
OR
libreofficelibreofficeMatch3.3.3
OR
libreofficelibreofficeMatch3.3.4
OR
libreofficelibreofficeMatch3.4.0
OR
libreofficelibreofficeMatch3.4.1
OR
libreofficelibreofficeMatch3.4.2
OR
libreofficelibreofficeMatch3.4.5
OR
libreofficelibreofficeMatch3.5

References

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

High

0.039 Low

EPSS

Percentile

92.0%