PT-2012-1020 · Document Foundation+3 · Libreoffice+4

Timo Warns

·

Published

2012-08-01

·

Updated

2023-02-13

·

CVE-2012-2665

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenOffice.org versions prior to 3.5.5 LibreOffice versions prior to 3.5.5
Description The issue is related to a buffer overflow in the XML manifest encryption tag parsing functionality. This can be exploited by a remote attacker using a crafted Open Document Text (.odt) file, potentially allowing them to execute arbitrary code, cause a denial of service, or access and modify confidential data. The exploitation can occur through various means, including a child tag within an incorrect parent tag, duplicate tags, or a Base64 ChecksumAttribute with a length not evenly divisible by four.
Recommendations For OpenOffice.org versions prior to 3.5.5, update to version 3.5.5 or later to resolve the issue. For LibreOffice versions prior to 3.5.5, update to version 3.5.5 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted Open Document Text (.odt) files and restricting access to sensitive data until the update is applied.

Fix

DoS

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2015-01305
CESA-2012_1135
CVE-2012-2665
DSA-2520-1
RHSA-2012:1135
RHSA-2012:1136
RHSA-2012_1135
RHSA-2012_1136

Affected Products

Centos
Libreoffice
Openoffice
Openoffice.Org
Red Hat