CVE Vulnerabilities

CVE-2005-0941

Published: May 02, 2005 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Openoffice Openoffice 1.0.1 (including) 1.0.1 (including)
Openoffice Openoffice 1.0.2 (including) 1.0.2 (including)
Openoffice Openoffice 1.1.0 (including) 1.1.0 (including)
Openoffice Openoffice 1.1.1 (including) 1.1.1 (including)
Openoffice Openoffice 1.1.2 (including) 1.1.2 (including)
Openoffice Openoffice 1.1.3 (including) 1.1.3 (including)
Openoffice Openoffice 1.1.4 (including) 1.1.4 (including)

References