V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2012-2665
DEB
Medium

Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.…

CVSS
6.8
Medium
EPSS
0.07
p93
Published
2012-01-01
Updated
2012-01-01
Description

Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.

Tags · CWE
RCE
CWE-122
CWE-787
CAPEC-92
Affected products
Ubuntu_linuxDebian_linuxEnterprise_linuxEnterprise_linux_desktopEnterprise_linux_for_ibm_z_systemsEnterprise_linux_for_power_big_endianEnterprise_linux_serverEnterprise_linux_server_from_rhui_6Enterprise_linux_workstation
CVSS vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Timeline
2012-01-01
Published
2012-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.070 · p93
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
libreofficeTracked
libreofficeTracked
openoffice.orgTracked
openoffice.orgTracked
openoffice.orgTracked
debian_linux*Tracked
enterprise_linux*Tracked
enterprise_linux_desktop*Tracked
enterprise_linux_for_ibm_z_systems*Tracked
enterprise_linux_for_power_big_endian*Tracked
enterprise_linux_server*Tracked
enterprise_linux_server_from_rhui_6*Tracked
enterprise_linux_workstation*Tracked
libreoffice*Tracked
openoffice*Tracked
ubuntu_linux*Tracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities