Vulnerability CVE-2015-5213


Published: 2015-11-10

Description:
Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a buffer overflow.

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Libreoffice -> Libreoffice 
Debian -> Debian linux 
Canonical -> Ubuntu linux 
Apache -> Openoffice 

 References:
http://rhn.redhat.com/errata/RHSA-2015-2619.html
http://www.debian.org/security/2015/dsa-3394
http://www.libreoffice.org/about-us/security/advisories/cve-2015-5213/
http://www.openoffice.org/security/cves/CVE-2015-5213.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
http://www.securityfocus.com/bid/77486
http://www.securitytracker.com/id/1034085
http://www.securitytracker.com/id/1034091
http://www.ubuntu.com/usn/USN-2793-1
https://security.gentoo.org/glsa/201603-05
https://security.gentoo.org/glsa/201611-03

Copyright 2020, cxsecurity.com

 

Back to Top