7.5
CVSSv2

CVE-2012-2665

Published: 06/08/2012 Updated: 13/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice prior to 3.5.5 allow remote malicious users to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache openoffice

libreoffice libreoffice

redhat enterprise linux 6.0

canonical ubuntu linux 11.04

redhat enterprise linux server from rhui 6 6.0

redhat enterprise linux for ibm z systems 6.0

canonical ubuntu linux 11.10

debian debian linux 7.0

debian debian linux 6.0

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux for power big endian 6.0

redhat enterprise linux workstation 6.0

canonical ubuntu linux 10.04

canonical ubuntu linux 12.04

Vendor Advisories

Synopsis Important: libreoffice security update Type/Severity Security Advisory: Important Topic Updated libreoffice packages that fix multiple security issues are nowavailable for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as havingimportant security impact A Commo ...
Synopsis Important: openofficeorg security update Type/Severity Security Advisory: Important Topic Updated openofficeorg packages that fix multiple security issues are nowavailable for Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as havingimportant security impact A ...
OpenOfficeorg could be made to crash or run programs as your login if it opened a specially crafted file ...
LibreOffice could be made to crash or run programs as your login if it opened a specially crafted file ...
Timo Warns from PRE-CERT discovered multiple heap-based buffer overflows in OpenOfficeorg, an office productivity suite The issues lies in the XML manifest encryption tag parsing code Using specially crafted files, an attacker can cause application crash and could cause arbitrary code execution For the stable distribution (squeeze), this proble ...