Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Sven Jacobi

#27620de 53,634
9.3CVSS total
Vulnerabilidades · 1
PT-2012-1204
9.3
2012-06-04
Document Foundation · Libreoffice · CVE-2012-2334
**Name of the Vulnerable Software and Affected Versions** OpenOffice.org versions 3.3 through 3.4 Beta LibreOffice versions prior to 3.5.3 **Description** The issue is related to an integer overflow in the `filter/source/msfilter/msdffimp.cxx` component, which can be triggered by the length of an Escher graphics record in a PowerPoint (.ppt) document. This can cause a denial of service (crash) and possibly allow remote attackers to execute arbitrary code, leading to unauthorized access to confidential data, disruption of service, or impact on data integrity. **Recommendations** For OpenOffice.org versions 3.3 through 3.4 Beta, consider updating to a version outside of this range to mitigate the risk. For LibreOffice versions prior to 3.5.3, update to version 3.5.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the `msdffimp.cxx` component or avoiding the opening of specially crafted PPT files until a patch is available.