CVE Vulnerabilities

CVE-2005-0941

Published: May 02, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
OpenofficeOpenoffice1.0.1 (including)1.0.1 (including)
OpenofficeOpenoffice1.0.2 (including)1.0.2 (including)
OpenofficeOpenoffice1.1.0 (including)1.1.0 (including)
OpenofficeOpenoffice1.1.1 (including)1.1.1 (including)
OpenofficeOpenoffice1.1.2 (including)1.1.2 (including)
OpenofficeOpenoffice1.1.3 (including)1.1.3 (including)
OpenofficeOpenoffice1.1.4 (including)1.1.4 (including)
Red Hat Enterprise Linux 3RedHatopenoffice.org-0:1.1.2-24.2.0.EL3*
Red Hat Enterprise Linux 4RedHatopenoffice.org-0:1.1.2-24.6.0.EL4*
Openoffice.org-l10nUbuntudapper*
Openoffice.org-l10nUbuntudevel*
Openoffice.org-l10nUbuntuedgy*
Openoffice.org-l10nUbuntufeisty*

References