VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : 脆弱性脅威分析用情報の定型データ配信
[ about VRDA Feed | JPCERT/CC



 
分析対象脆弱性情報 (リビジョン番号 : 1) [ Download XML
CVE-2012-2334
openoffice.org, libreoffice: Integer overflow in filter/source/msfilter/msdffimp...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2334

原文

Integer overflow in filter/source/msfilter/msdffimp.cxx in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the length of an Escher graphics record in a PowerPoint (.ppt) document, which triggers a buffer overflow.

翻訳   (表示)





この情報について
分析情報提供元:
NIST NVD
初版公開日:
2012-06-19
分析対象脆弱性情報の分類:
アドバイザリ・注意喚起
最終更新日:
2012-06-20




脆弱性の影響を受ける製品の識別子
cpe:/a:apache:openoffice.org:3.3
cpe:/a:apache:openoffice.org:3.4:beta
cpe:/a:libreoffice:libreoffice:3.3.0
cpe:/a:libreoffice:libreoffice:3.3.1
cpe:/a:libreoffice:libreoffice:3.3.2
cpe:/a:libreoffice:libreoffice:3.3.3
cpe:/a:libreoffice:libreoffice:3.3.4
cpe:/a:libreoffice:libreoffice:3.4.0
cpe:/a:libreoffice:libreoffice:3.4.1
cpe:/a:libreoffice:libreoffice:3.4.2
cpe:/a:libreoffice:libreoffice:3.4.5
cpe:/a:libreoffice:libreoffice:3.5
cpe:/a:libreoffice:libreoffice:3.5.2 and previous versions
 


脆弱性の分析内容
[攻撃元区分]  [?]
未評価 [?]

ローカル [?]
隣接 [?]
X ネットワーク [?]

[攻撃条件の複雑さ]  [?]
未評価 [?]

 [?]
X [?]
 [?]

[攻撃前の認証要否]  [?]
未評価 [?]

複数 [?]
単一 [?]
X 不要 [?]

[機密性への影響]  [?]
未評価 [?]

影響なし [?]
X 部分的 [?]
全面的 [?]

[完全性への影響]  [?]
未評価 [?]

影響なし [?]
X 部分的 [?]
全面的 [?]

[可用性への影響]  [?]
未評価 [?]

影響なし [?]
X 部分的 [?]
全面的 [?]

関連情報




参考情報
BID 53570




CONFIRM http://cgit.freedesktop.org/libreoffice/core/commit/?id=512401decb286ba0fc3031939b8f7de8649c502e




CONFIRM http://cgit.freedesktop.org/libreoffice/core/commit/?id=28a6558f9d3ca2dda3191f8b5b3f2378ee2533da




CONFIRM http://www.openoffice.org/security/cves/CVE-2012-2334.html




CONFIRM http://www.libreoffice.org/advisories/cve-2012-2334/




DEBIAN DSA-2487




FEDORA FEDORA-2012-8114




MANDRIVA MDVSA-2012:091




MANDRIVA MDVSA-2012:090




MISC https://bugzilla.redhat.com/show_bug.cgi?id=821803




MLIST [oss-security] 20120528 Kind request to update upstream CVE-2012-2334 advisories they to reflect arbitrary code execution possibility too and OSS list notification




OSVDB 82517




REDHAT RHSA-2012:0705




SECTRACK 1027070




SECUNIA 49392




SECUNIA 49373




SECUNIA 47244




SECUNIA 46992




Vulnerability Type Numeric Errors (CWE-189)





Copyright © 2012 JPCERT/CC All Rights Reserved.