PT-2011-1226 · Document Foundation · Libreoffice

Josh Bressers

·

Publicado

2011-07-21

·

Atualizado

2012-01-19

·

CVE-2011-2685

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LibreOffice versions prior to 3.3.3
Description The issue is related to a stack-based buffer overflow in the Lotus Word Pro import filter, which can be exploited by remote attackers via a crafted .lwp file. This can lead to arbitrary code execution. The vulnerability may allow an attacker to gain unauthorized access to confidential data, cause a denial of service, or impact data integrity.
Recommendations For versions prior to 3.3.3, update to version 3.3.3 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the Lotus Word Pro import filter until a patch is applied. Restrict access to .lwp files to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-02949
CVE-2011-2685
DSA-2275-1

Produtos afetados

Libreoffice