Vulnerability Name:

CVE-2007-0002 (CCN-33109)

Assigned:2006-12-19
Published:2007-03-16
Updated:2018-10-16
Summary:Multiple heap-based buffer overflows in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allow user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file in which values to loop counters are not properly handled in the (1) WP3TablesGroup::_readContents and (2) WP5DefinitionGroup_DefineTablesSubGroup::WP5DefinitionGroup_DefineTablesSubGroup functions.
Note: the integer overflow has been split into CVE-2007-1466.
CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2007-0002

Source: FEDORA
Type: UNKNOWN
FEDORA-2007-350

Source: IDEFENSE
Type: UNKNOWN
20070316 Multiple Vendor libwpd Multiple Buffer Overflow Vulnerabilities

Source: SUSE
Type: UNKNOWN
SUSE-SA:2007:023

Source: CCN
Type: RHSA-2007-0055
Important: libwpd security update

Source: SECUNIA
Type: Vendor Advisory
24465

Source: CCN
Type: SA24507
libwpd Multiple Heap-based Buffer Overflow Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
24507

Source: SECUNIA
Type: Vendor Advisory
24557

Source: SECUNIA
Type: Vendor Advisory
24572

Source: SECUNIA
Type: Vendor Advisory
24573

Source: SECUNIA
Type: Vendor Advisory
24580

Source: SECUNIA
Type: Vendor Advisory
24581

Source: CCN
Type: SA24588
OpenOffice.org Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
24588

Source: SECUNIA
Type: Vendor Advisory
24591

Source: SECUNIA
Type: Vendor Advisory
24593

Source: SECUNIA
Type: Vendor Advisory
24613

Source: SECUNIA
Type: Vendor Advisory
24794

Source: CCN
Type: SA24856
Sun StarOffice and StarSuite 8 WordPerfect Vulnerability

Source: SECUNIA
Type: Vendor Advisory
24856

Source: SECUNIA
Type: Vendor Advisory
24906

Source: GENTOO
Type: UNKNOWN
GLSA-200704-07

Source: CCN
Type: SECTRACK ID: 1017789
libwpd Buffer Overflows Let Remote Users Execute Arbitrary Code

Source: SLACKWARE
Type: UNKNOWN
SSA-2007-085-02

Source: CCN
Type: SourceForge.net: Files
WordPerfect Document importer/exporter - File Release Notes and Changelog - Release Name: libwpd-0.8.9

Source: CONFIRM
Type: UNKNOWN
http://sourceforge.net/project/shownotes.php?release_id=494122

Source: CCN
Type: libwpd Web site
SourceForge.net: WordPerfect Document importer/exporter

Source: CCN
Type: Sun Alert ID: 102863
Security Vulnerability in StarOffice 8 May Lead to Heap Overflow and Arbitrary Code Execution

Source: SUNALERT
Type: UNKNOWN
102863

Source: CCN
Type: ASA-2007-164
Security Vulnerability in StarOffice 8 May Lead to Heap Overflow and Arbitrary Code Execution (Sun 102863)

Source: CCN
Type: Abiword Web site
AbiWord

Source: DEBIAN
Type: UNKNOWN
DSA-1268

Source: DEBIAN
Type: UNKNOWN
DSA-1270

Source: DEBIAN
Type: DSA-1268
libwpd -- integer overflow

Source: DEBIAN
Type: DSA-1270
openoffice.org -- several vulnerabilities

Source: CCN
Type: GLSA-200704-07
libwpd: Multiple vulnerabilities

Source: CCN
Type: GLSA-200704-12
OpenOffice.org: Multiple vulnerabilities

Source: GENTOO
Type: UNKNOWN
GLSA-200704-12

Source: CCN
Type: KWord Web site
The KOffice Project - KWord

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2007:063

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2007:064

Source: CCN
Type: OpenOffice.org Web site
OpenOffice.org: Home

Source: REDHAT
Type: Vendor Advisory
RHSA-2007:0055

Source: BUGTRAQ
Type: UNKNOWN
20070316 rPSA-2007-0057-1 libwpd

Source: BID
Type: UNKNOWN
23006

Source: CCN
Type: BID-23006
LibWPD Library Multiple Buffer Overflow Vulnerabilities

Source: SECTRACK
Type: UNKNOWN
1017789

Source: CCN
Type: TLSA-2007-27
Buffer overflow

Source: CCN
Type: USN-437-1
libwpd vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-437-1

Source: VUPEN
Type: Vendor Advisory
ADV-2007-0976

Source: VUPEN
Type: Vendor Advisory
ADV-2007-1032

Source: VUPEN
Type: Vendor Advisory
ADV-2007-1339

Source: XF
Type: UNKNOWN
libwpd-multiple-bo(33109)

Source: CCN
Type: iDefense Labs PUBLIC ADVISORY: 03.16.07
Multiple Vendor libwpd Multiple Buffer Overflow Vulnerabilities

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:11535

Source: SUSE
Type: SUSE-SA:2007:023
OpenOffice_org security update

Vulnerable Configuration:Configuration 1:
  • cpe:/a:libwpd:libwpd_library:0.8.2:*:*:*:*:*:*:*
  • OR cpe:/a:libwpd:libwpd_library:0.8.6:*:*:*:*:*:*:*
  • OR cpe:/a:libwpd:libwpd_library:0.8.7:*:*:*:*:*:*:*
  • OR cpe:/a:libwpd:libwpd_library:*:*:*:*:*:*:*:* (Version <= 0.8.8)

  • Configuration RedHat 1:
  • cpe:/a:redhat:rhel_productivity:5:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:5::client_workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:openoffice:openoffice.org:*:*:*:*:*:*:*:*
  • OR cpe:/a:kde:kword:1.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:abisource:abiword:3.0.2-2:*:*:*:*:*:*:*
  • AND
  • cpe:/o:sun:solaris:8::x86:*:*:*:*:*
  • OR cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:sun:solaris:8::sparc:*:*:*:*:*
  • OR cpe:/o:novell:linux_desktop:9:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.1:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:10.0::oss:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:6.06::lts:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:10.1::personal:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007::x86_64:*:*:*:*:*
  • OR cpe:/o:turbolinux:turbolinux:fuji:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5:*:client_workstation:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:7.04:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5:*:client:*:*:*:*:*
  • OR cpe:/a:sun:staroffice:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:10.2:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:9.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20070002
    V
    CVE-2007-0002
    2022-06-30
    oval:org.opensuse.security:def:112920
    P
    libwpd-0_10-10-0.10.3-2.3 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:106375
    P
    libwpd-0_10-10-0.10.3-2.3 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:26129
    P
    Security update for gtk-vnc (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:36504
    P
    libwpd-0_8-8-0.8.14-4.33 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:26065
    P
    Security update for polkit (Important)
    2021-06-03
    oval:org.opensuse.security:def:26053
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:26054
    P
    Security update for flac (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:27467
    P
    libnewt0_52 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26479
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:26771
    P
    libvirt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26257
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27502
    P
    libwpd-0_8-8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26630
    P
    perl-spamassassin on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26785
    P
    mozilla-xulrunner192 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26338
    P
    Security update for Chromium (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26683
    P
    dbus-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26829
    P
    systemtap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26395
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:26732
    P
    kvm on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:18862
    P
    DSA-1268-1 libwpd - integer overflow
    2014-06-23
    oval:org.mitre.oval:def:21704
    P
    ELSA-2007:0055: libwpd security update (Important)
    2014-05-26
    oval:org.mitre.oval:def:11535
    V
    Multiple heap-based buffer overflows in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allow user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file in which values to loop counters are not properly handled in the (1) WP3TablesGroup::_readContents and (2) WP5DefinitionGroup_DefineTablesSubGroup::WP5DefinitionGroup_DefineTablesSubGroup functions. NOTE: the integer overflow has been split into CVE-2007-1466.
    2013-04-29
    oval:org.debian:def:1270
    V
    several vulnerabilities
    2013-01-21
    oval:com.redhat.rhsa:def:20070055
    P
    RHSA-2007:0055: libwpd security update (Important)
    2008-03-20
    oval:org.debian:def:1268
    V
    integer overflow
    2007-03-17
    BACK
    libwpd libwpd library 0.8.2
    libwpd libwpd library 0.8.6
    libwpd libwpd library 0.8.7
    libwpd libwpd library *
    openoffice openoffice.org *
    kde kword 1.4.2
    abisource abiword 3.0.2-2
    sun solaris 8
    gentoo linux *
    sun solaris 8
    novell linux desktop 9
    debian debian linux 3.1
    suse suse linux 10.0
    canonical ubuntu 6.06
    suse suse linux 10.1
    mandrakesoft mandrake linux 2007
    mandrakesoft mandrake linux 2007
    turbolinux turbolinux fuji
    redhat enterprise linux 5
    canonical ubuntu 7.04
    redhat enterprise linux 5
    sun staroffice 8.0
    novell opensuse 10.2
    suse suse linux 9.3