9.3
CVSSv2

CVE-2007-0245

Published: 12/06/2007 Updated: 16/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and previous versions allows remote malicious users to execute arbitrary code via a RTF file with a crafted prtdata tag with a length parameter inconsistency, which causes vtable entries to be overwritten.

Vulnerable Product Search on Vulmon Subscribe to Product

openoffice openoffice

Vendor Advisories

John Heasman discovered that OpenOffice did not correctly validate the sizes of tags in RTF documents If a user were tricked into opening a specially crafted document, a remote attacker could execute arbitrary code with user privileges ...
John Heasman discovered a heap overflow in the routines of OpenOfficeorg that parse RTF files A specially crafted RTF file could cause the filter to overwrite data on the heap, which may lead to the execution of arbitrary code For the old stable distribution (sarge) this problem has been fixed in version 113-9sarge7 For the stable distributio ...