Описание
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document, related to a "numeric truncation error," a different vulnerability than CVE-2008-2152.
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | not-affected | built with --with-alloc=system |
| devel | not-affected | built with --with-alloc=system |
| feisty | not-affected | built with --with-alloc=system |
| gutsy | not-affected | built with --with-alloc=system |
| hardy | not-affected | built with --with-alloc=system |
| intrepid | not-affected | built with --with-alloc=system |
| upstream | needs-triage |
Показывать по
Ссылки на источники
EPSS
9.3 Critical
CVSS2
7.8 High
CVSS3
Связанные уязвимости
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document, related to a "numeric truncation error," a different vulnerability than CVE-2008-2152.
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document, related to a "numeric truncation error," a different vulnerability than CVE-2008-2152.
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/ ...
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document, related to a "numeric truncation error," a different vulnerability than CVE-2008-2152.
EPSS
9.3 Critical
CVSS2
7.8 High
CVSS3