CVE Vulnerabilities

CVE-2012-2149

Published: Jun 21, 2012 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

The WPXContentListener::_closeTableRow function in WPXContentListener.cpp in libwpd 0.8.8, as used by OpenOffice.org (OOo) before 3.4, allows remote attackers to execute arbitrary code via a crafted Wordperfect .WPD document that causes a negative array index to be used. NOTE: some sources report this issue as an integer overflow.

Affected Software

Name Vendor Start Version End Version
Enterprise_linux__optional_productivity_applications Redhat * *
Enterprise_linux_desktop Redhat 5.0 (including) 5.0 (including)
Red Hat Enterprise Linux 5 RedHat libwpd-0:0.8.7-3.1.el5_8 *
Libreoffice Ubuntu devel *
Libreoffice Ubuntu natty *
Libreoffice Ubuntu oneiric *
Libreoffice Ubuntu precise *
Libwpd Ubuntu hardy *
Libwpd Ubuntu upstream *
Openoffice.org Ubuntu hardy *
Openoffice.org Ubuntu lucid *

References