Vulnerability Name: | CVE-2007-0245 (CCN-34843) | ||||||||||||||||||||||||||||
Assigned: | 2007-06-12 | ||||||||||||||||||||||||||||
Published: | 2007-06-12 | ||||||||||||||||||||||||||||
Updated: | 2018-10-16 | ||||||||||||||||||||||||||||
Summary: | Heap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with a crafted prtdata tag with a length parameter inconsistency, which causes vtable entries to be overwritten. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||
References: | Source: SGI Type: UNKNOWN 20070602-01-P Source: CCN Type: BugTraq Mailing List, Wed Jun 13 2007 - 12:15:50 CDT High risk vulnerability in OpenOffice RTF parser Source: MITRE Type: CNA CVE-2007-0245 Source: OSVDB Type: UNKNOWN 35378 Source: CCN Type: RHSA-2007-0406 Important: openoffice.org security update Source: CCN Type: SA25648 OpenOffice RTF File and FreeType Font Parsing Vulnerabilities Source: SECUNIA Type: Vendor Advisory 25648 Source: SECUNIA Type: Vendor Advisory 25650 Source: SECUNIA Type: Vendor Advisory 25673 Source: CCN Type: SA25705 Sun StarOffice Office Suite RTF File and FreeType Font Parsing Vulnerabilities Source: SECUNIA Type: Vendor Advisory 25705 Source: SECUNIA Type: Vendor Advisory 25862 Source: SECUNIA Type: Vendor Advisory 25894 Source: SECUNIA Type: Vendor Advisory 25905 Source: SECUNIA Type: Vendor Advisory 26010 Source: SECUNIA Type: Vendor Advisory 26022 Source: SECUNIA Type: Vendor Advisory 26476 Source: CCN Type: SECTRACK ID: 1018239 OpenOffice.org Office Suite Heap Overflow in Parsing RTF Files Lets Remote Users Execute Arbitrary Code Source: CCN Type: Sun Alert ID: 102917 Security Vulnerability with Manipulated RTF Files May Lead to Heap Overflows and Arbitrary Code Execution Source: SUNALERT Type: UNKNOWN 102917 Source: CCN Type: ASA-2007-278 Security Vulnerability with Manipulated RTF Files May Lead to Heap Overflows and Arbitrary Code Execution (Sun 102917) Source: CCN Type: ASA-2007-328 OpenOffice.org security update (RHSA-2007-0406) Source: CONFIRM Type: UNKNOWN http://sw.openoffice.org/source/browse/sw/sw/source/filter/rtf/swparrtf.cxx?rev=1.67 Source: DEBIAN Type: Patch DSA-1307 Source: DEBIAN Type: DSA-1307 openoffice.org -- heap overflow Source: CCN Type: GLSA-200707-02 OpenOffice.org: Two buffer overflows Source: GENTOO Type: UNKNOWN GLSA-200707-02 Source: MANDRIVA Type: UNKNOWN MDKSA-2007:144 Source: SUSE Type: UNKNOWN SUSE-SA:2007:037 Source: CCN Type: OpenOffice.org Web site OpenOffice.org: Home Source: CCN Type: OSVDB ID: 35378 OpenOffice.org (OOo) RTF File Parsing prtdata Tag Overflow Source: REDHAT Type: UNKNOWN RHSA-2007:0406 Source: BUGTRAQ Type: UNKNOWN 20070613 High risk vulnerability in OpenOffice RTF parser Source: BID Type: UNKNOWN 24450 Source: CCN Type: BID-24450 OpenOffice RTF File Parser Buffer Overflow Vulnerability Source: SECTRACK Type: UNKNOWN 1018239 Source: CCN Type: USN-482-1 OpenOffice.org vulnerability Source: UBUNTU Type: UNKNOWN USN-482-1 Source: VUPEN Type: Vendor Advisory ADV-2007-2166 Source: VUPEN Type: Vendor Advisory ADV-2007-2229 Source: XF Type: UNKNOWN openoffice-rtf-bo(34843) Source: XF Type: UNKNOWN openoffice-rtf-bo(34843) Source: CONFIRM Type: UNKNOWN https://issues.rpath.com/browse/RPL-1570 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10002 Source: SUSE Type: SUSE-SA:2007:037 OpenOffice_org RTF import problem | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration RedHat 8: ![]() | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |