CVE Vulnerabilities

CVE-2008-2152

Published: Jun 10, 2008 | Modified: Sep 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Openoffice.org Openoffice 2.0 (including) 2.0 (including)
Openoffice.org Openoffice 2.1 (including) 2.1 (including)
Openoffice.org Openoffice 2.2 (including) 2.2 (including)
Openoffice.org Openoffice 2.3 (including) 2.3 (including)
Openoffice.org Openoffice 2.4 (including) 2.4 (including)
Red Hat Enterprise Linux 3 RedHat openoffice.org-0:1.1.2-42.2.0.EL3 *
Red Hat Enterprise Linux 4 RedHat openoffice.org2-1:2.0.4-5.7.0.5.0 *
Red Hat Enterprise Linux 4 RedHat openoffice.org-0:1.1.5-10.6.0.5.EL4 *
Red Hat Enterprise Linux 5 RedHat openoffice.org-1:2.3.0-6.5.1.el5_2 *

References