simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x prior to 3.3 does not properly handle integer values associated with dictionary property items, which allows remote malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an "integer truncation error."
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
openoffice openoffice.org 3.2.1 |