Уязвимость DoS атаки через некорректную обработку итераторов в классе WPXTableList в libwpd в приложении LibreOffice
Описание
В файлах WP1StylesListener.cpp, WP5StylesListener.cpp и WP42StylesListener.cpp в библиотеке libwpd версии 0.10.1 некорректно обрабатываются итераторы. Это позволяет злоумышленникам провести DoS атаку путем чтения данных вне границ буфера в классе WPXTableList в файле WPXTable.cpp.
Затронутые версии ПО
LibreOffice до версии 5.3.7
Тип уязвимости
DoS атака через чтение данных вне границ буфера (heap-based buffer over-read)
Ссылки
- Issue TrackingThird Party Advisory
- Issue TrackingThird Party Advisory
- Mailing ListThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Issue TrackingThird Party Advisory
- Issue TrackingThird Party Advisory
- Issue TrackingThird Party Advisory
- Mailing ListThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Issue TrackingThird Party Advisory
Уязвимые конфигурации
Одно из
EPSS
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
WP1StylesListener.cpp, WP5StylesListener.cpp, and WP42StylesListener.cpp in libwpd 0.10.1 mishandle iterators, which allows remote attackers to cause a denial of service (heap-based buffer over-read in the WPXTableList class in WPXTable.cpp). This vulnerability can be triggered in LibreOffice before 5.3.7. It may lead to suffering a remote attack against a LibreOffice application.
WP1StylesListener.cpp, WP5StylesListener.cpp, and WP42StylesListener.cpp in libwpd 0.10.1 mishandle iterators, which allows remote attackers to cause a denial of service (heap-based buffer over-read in the WPXTableList class in WPXTable.cpp). This vulnerability can be triggered in LibreOffice before 5.3.7. It may lead to suffering a remote attack against a LibreOffice application.
WP1StylesListener.cpp, WP5StylesListener.cpp, and WP42StylesListener.c ...
EPSS
7.5 High
CVSS3
5 Medium
CVSS2