CVE-2012-1149
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.2%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 14.17% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- libreoffice/libreoffice · debian/debian linux · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux workstation · apache/openoffice.org · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- http://archives.neohapsis.com/archives/bugtraq/2012-05/0089.htmlBroken Link
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082168.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081319.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0705.htmlThird Party Advisory
- http://secunia.com/advisories/46992
- http://secunia.com/advisories/47244
- http://secunia.com/advisories/49140
- http://secunia.com/advisories/49373
- http://secunia.com/advisories/49392Vendor Advisory
- http://secunia.com/advisories/50692
- http://secunia.com/advisories/60799
- http://security.gentoo.org/glsa/glsa-201209-05.xmlThird Party Advisory
- http://securitytracker.com/id?1027068Patch, Third Party Advisory, VDB Entry
- http://www.debian.org/security/2012/dsa-2473Third Party Advisory
- http://www.debian.org/security/2012/dsa-2487Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlThird Party Advisory
- http://www.libreoffice.org/advisories/cve-2012-1149/Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:090Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:091Broken Link
- http://www.openoffice.org/security/cves/CVE-2012-1149.htmlThird Party Advisory
- http://www.osvdb.org/81988Broken Link
- http://www.securityfocus.com/bid/53570Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75692
- http://archives.neohapsis.com/archives/bugtraq/2012-05/0089.htmlBroken Link
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082168.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081319.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0705.htmlThird Party Advisory
- http://secunia.com/advisories/46992
- http://secunia.com/advisories/47244
- http://secunia.com/advisories/49140
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.