Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24144
HistoryApr 10, 2020 - 12:47 a.m.

Arbitrary Code Execution

2020-04-1000:47:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.548 Medium

EPSS

Percentile

97.7%

OpenOffice.org is vulnerable to arbitrary code execution. An integer underflow flaw and a boundary error flaw, both possibly leading to a heap-based buffer overflow, were found in the way OpenOffice.org parsed certain records in Microsoft Word documents. An attacker could create a specially-crafted Microsoft Word document, which once opened by a local, unsuspecting user, could cause OpenOffice.org to crash or, potentially, execute arbitrary code with the permissions of the user running OpenOffice.org.

References