7.5

CVE-2012-1149

Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LibreofficeLibreoffice Version <= 3.5.2
DebianDebian Linux Version6.0
DebianDebian Linux Version7.0
RedhatEnterprise Linux Version5.0
ApacheOpenoffice.Org Version3.3.0
ApacheOpenoffice.Org Version3.4 Updatebeta
FedoraprojectFedora Version15
FedoraprojectFedora Version16
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.19% 0.783
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/bid/53570
Third Party Advisory
VDB Entry
http://securitytracker.com/id?1027068
Patch
Third Party Advisory
VDB Entry