Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1774

Опубликовано: 27 апр. 2015
Источник: redhat
CVSS2: 4.6

Описание

The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.

A flaw was found in the way the LibreOffice HWP (Hangul Word Processor) file filter processed certain HWP documents. An attacker able to trick a user into opening a specially crafted HWP document could possibly use this flaw to execute arbitrary code with the privileges of the user opening that document.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5openoffice.orgAffected
Red Hat Enterprise Linux 6libreofficeFixedRHSA-2015:145821.07.2015
Red Hat Enterprise Linux 7glmFixedRHBA-2015:219723.11.2015
Red Hat Enterprise Linux 7inkscapeFixedRHBA-2015:219723.11.2015
Red Hat Enterprise Linux 7libabwFixedRHBA-2015:219723.11.2015
Red Hat Enterprise Linux 7libcdrFixedRHBA-2015:219723.11.2015
Red Hat Enterprise Linux 7libetonyekFixedRHBA-2015:219723.11.2015
Red Hat Enterprise Linux 7libfreehandFixedRHBA-2015:219723.11.2015
Red Hat Enterprise Linux 7libmspubFixedRHBA-2015:219723.11.2015
Red Hat Enterprise Linux 7libmwawFixedRHBA-2015:219723.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-129->CWE-20->CWE-252->CWE-822
https://bugzilla.redhat.com/show_bug.cgi?id=1216042libreoffice: HWP file filter vulnerability

4.6 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.

nvd
больше 10 лет назад

The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.

debian
больше 10 лет назад

The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and ...

github
больше 3 лет назад

The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.

oracle-oval
больше 10 лет назад

ELSA-2015-1458: libreoffice security, bug fix, and enhancement update (MODERATE)

4.6 Medium

CVSS2