Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23777
HistoryApr 10, 2020 - 12:35 a.m.

Arbitrary Code Execution

2020-04-1000:35:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

0.334 Low

EPSS

Percentile

97.1%

openoffice.org is vulnerable to arbitrary code execution. An integer underflow flaw and a boundary error flaw, both possibly leading to a heap-based buffer overflow, were found in the way OpenOffice.org parses certain records in Microsoft Word documents. An attacker could create a specially-crafted Microsoft Word document, which once opened by an unsuspecting user, could cause OpenOffice.org to crash or, potentially, execute arbitrary code with the permissions of the user running OpenOffice.org.

References