Vulnerability CVE-2014-3575


Published: 2014-08-26   Modified: 2014-08-27

Description:
The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to embed arbitrary data into documents via crafted OLE objects.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
OpenOffice Targeted Data Exposure Using Crafted OLE Objects
Herbert
23.08.2014

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
SUN -> Openoffice.org 
Redhat -> Enterprise linux desktop 
Redhat -> Enterprise linux server 
Redhat -> Enterprise linux workstation 
Apache -> Openoffice 
Apache -> Openoffice.org 

 References:
http://archives.neohapsis.com/archives/bugtraq/2014-08/0115.html
http://blog.documentfoundation.org/2014/08/28/libreoffice-4-3-1-fresh-announced/
http://lists.fedoraproject.org/pipermail/package-announce/2014-September/137657.html
http://rhn.redhat.com/errata/RHSA-2015-0377.html
http://secunia.com/advisories/59600
http://secunia.com/advisories/59877
http://www.openoffice.org/security/cves/CVE-2014-3575.html
http://www.securityfocus.com/bid/69354
http://www.securitytracker.com/id/1030754
http://xforce.iss.net/xforce/xfdb/95420
https://security.gentoo.org/glsa/201603-05

Copyright 2024, cxsecurity.com

 

Back to Top