PT-2008-1153 · Apache+1 · Openoffice+1
Publicado
2008-10-30
·
Atualizado
2017-09-29
·
CVE-2008-2238
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenOffice versions 2.x before 2.4.2
Description
The issue is related to an integer overflow in the handling of EMF files, specifically with crafted EMR records. This can lead to a heap-based buffer overflow, allowing a remote attacker to execute arbitrary code, access confidential data, compromise data integrity, and cause a denial of service. The exploitation is possible through specially crafted EMR records in an EMF file associated with a document.
Recommendations
For OpenOffice versions 2.x before 2.4.2, update to version 2.4.2 or later to resolve the issue. As a temporary workaround, consider restricting the opening of documents from untrusted sources, especially those containing EMF files, to minimize the risk of exploitation. Avoid using the affected software to open specially crafted EMF files until the issue is resolved.
Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openoffice
Red Hat