PT-2011-1226 · Document Foundation · Libreoffice
Josh Bressers
·
Publicado
2011-07-21
·
Atualizado
2012-01-19
·
CVE-2011-2685
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
LibreOffice versions prior to 3.3.3
Description
The issue is related to a stack-based buffer overflow in the Lotus Word Pro import filter, which can be exploited by remote attackers via a crafted .lwp file. This can lead to arbitrary code execution. The vulnerability may allow an attacker to gain unauthorized access to confidential data, cause a denial of service, or impact data integrity.
Recommendations
For versions prior to 3.3.3, update to version 3.3.3 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the Lotus Word Pro import filter until a patch is applied. Restrict access to .lwp files to minimize the risk of exploitation.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Libreoffice