CVE Vulnerabilities

CVE-2012-1149

Published: Jun 21, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
LibreofficeLibreoffice*3.5.2 (including)
Red Hat Enterprise Linux 5RedHatopenoffice.org-1:3.1.1-19.10.el5_8.3*
Red Hat Enterprise Linux 6RedHatopenoffice.org-1:3.2.1-19.6.el6_2.7*
LibreofficeUbuntunatty*
LibreofficeUbuntuoneiric*
LibreofficeUbuntuupstream*
Openoffice.orgUbuntuhardy*
Openoffice.orgUbuntulucid*

References