Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24145
HistoryApr 10, 2020 - 12:47 a.m.

Arbitrary Code Execution

2020-04-1000:47:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.374 Low

EPSS

Percentile

97.2%

OpenOffice.org is vulnerable to arbitrary code execution. An integer underflow flaw and a boundary error flaw, both possibly leading to a heap-based buffer overflow, were found in the way OpenOffice.org parsed certain records in Microsoft Word documents. An attacker could create a specially-crafted Microsoft Word document, which once opened by a local, unsuspecting user, could cause OpenOffice.org to crash or, potentially, execute arbitrary code with the permissions of the user running OpenOffice.org.

References