CVE-2008-3282
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly execute…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document, related to a "numeric truncation error," a different vulnerability than CVE-2008-2152.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 10.76% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-681
- Affected
- apache/openoffice · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/31640Broken Link
- http://secunia.com/advisories/31646Broken Link
- http://secunia.com/advisories/31778Broken Link
- http://securitytracker.com/id?1020764Broken Link, Third Party Advisory, VDB Entry
- http://www.openoffice.org/issues/show_bug.cgi?id=92217Issue Tracking
- http://www.redhat.com/support/errata/RHSA-2008-0835.htmlBroken Link
- http://www.securityfocus.com/bid/30866Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/2449Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=455867Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=458056Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44742Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11345Broken Link
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00120.htmlMailing List
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00494.htmlMailing List
- http://secunia.com/advisories/31640Broken Link
- http://secunia.com/advisories/31646Broken Link
- http://secunia.com/advisories/31778Broken Link
- http://securitytracker.com/id?1020764Broken Link, Third Party Advisory, VDB Entry
- http://www.openoffice.org/issues/show_bug.cgi?id=92217Issue Tracking
- http://www.redhat.com/support/errata/RHSA-2008-0835.htmlBroken Link
- http://www.securityfocus.com/bid/30866Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/2449Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=455867Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=458056Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44742Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11345Broken Link
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00120.htmlMailing List
- https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00494.htmlMailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.