LWN.net Logo

libreoffice: code execution

Package(s):libreoffice CVE #(s):CVE-2012-2665
Created:August 2, 2012 Updated:August 14, 2012
Description:

From the Red Hat advisory:

Multiple heap-based buffer overflow flaws were found in the way LibreOffice processed encryption information in the manifest files of OpenDocument Format files. An attacker could provide a specially-crafted OpenDocument Format file that, when opened in a LibreOffice application, would cause the application to crash or, potentially, execute arbitrary code with the privileges of the user running the application.

Alerts:
Red Hat RHSA-2012:1135-01 2012-08-01
Red Hat RHSA-2012:1136-01 2012-08-01
CentOS CESA-2012:1135 2012-08-02
CentOS CESA-2012:1136 2012-08-02
Oracle ELSA-2012-1135 2012-08-02
Scientific Linux SL-libr-20120802 2012-08-02
Scientific Linux SL-open-20120802 2012-08-02
Debian DSA-2520-1 2012-08-02
Mandriva MDVSA-2012:123 2012-08-04
Mandriva MDVSA-2012:124 2012-08-04
Fedora FEDORA-2012-11402 2012-08-10
Ubuntu USN-1536-1 2012-08-13
Ubuntu USN-1537-1 2012-08-13
Mageia MGASA-2012-0253 2012-09-04
Gentoo 201209-05 2012-09-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds