Skip to main content

OpenOffice.org Documents Parsing Code Execution Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 2 Sep 2009 4531 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in OpenOffice.org, which could be exploited by attackers to compromise a vulnerable system.

1. Due to an integer underflow error when parsing certain records in a Word document table, which could allow attackers to crash an affected application or execute arbitrary code by tricking a user into opening a specially crafted Word document.

2. Due to a heap overflow error when parsing certain records in a Word document, which could allow attackers to crash an affected application or execute arbitrary code by tricking a user into opening a malicious Word document.


Impact

  • Remote Code Execution

System / Technologies affected

  • OpenOffice.org versions prior to 3.1.1

Solutions


Vulnerability Identifier


Source


Related Link