7.5
CVSSv2

CVE-2014-9093

Published: 26/11/2014 Updated: 03/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

LibreOffice prior to 4.3.5 allows remote malicious users to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file.

Vulnerable Product Search on Vulmon Subscribe to Product

libreoffice libreoffice

fedoraproject fedora 20

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 14.10

debian debian linux 7.0

Vendor Advisories

Debian Bug report logs - #771163 libreoffice: CVE-2014-9093 Package: libreoffice; Maintainer for libreoffice is Debian LibreOffice Maintainers <debian-openoffice@listsdebianorg>; Source for libreoffice is src:libreoffice (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 27 Nov 2014 0 ...
LibreOffice could be made to crash or run programs as your login if it opened a specially crafted file ...
It was discovered that LibreOffice, an office productivity suite, could try to write to invalid memory areas when importing malformed RTF files This could allow remote attackers to cause a denial of service (crash) or arbitrary code execution via crafted RTF files For the stable distribution (wheezy), this problem has been fixed in version 1:35 ...