CVE Vulnerabilities

CVE-2012-2149

Published: Jun 21, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The WPXContentListener::_closeTableRow function in WPXContentListener.cpp in libwpd 0.8.8, as used by OpenOffice.org (OOo) before 3.4, allows remote attackers to execute arbitrary code via a crafted Wordperfect .WPD document that causes a negative array index to be used. NOTE: some sources report this issue as an integer overflow.

Affected Software

NameVendorStart VersionEnd Version
Enterprise_linux__optional_productivity_applicationsRedhat**
Enterprise_linux_desktopRedhat5.0 (including)5.0 (including)
Red Hat Enterprise Linux 5RedHatlibwpd-0:0.8.7-3.1.el5_8*
LibreofficeUbuntudevel*
LibreofficeUbuntunatty*
LibreofficeUbuntuoneiric*
LibreofficeUbuntuprecise*
LibwpdUbuntuhardy*
LibwpdUbuntuupstream*
Openoffice.orgUbuntuhardy*
Openoffice.orgUbuntulucid*

References