SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-2665

Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open…

HIGH 7.5EPSS 7.01%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (7.01%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
7.01% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-787
Affected
apache/openoffice · libreoffice/libreoffice · canonical/ubuntu linux · debian/debian linux · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux for ibm z systems · redhat/enterprise linux for power big endian · redhat/enterprise linux server · redhat/enterprise linux server from rhui 6 · redhat/enterprise linux workstation
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.