HIGH · 7.5

CVE-2012-1149

Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application cr...

Vulnerability Description

Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
LibreofficeLibreoffice<= 3.5.2
DebianDebian Linux6.0
RedhatEnterprise Linux5.0
RedhatEnterprise Linux Desktop5.0
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server Aus6.2
RedhatEnterprise Linux Server Eus6.2.z
RedhatEnterprise Linux Workstation6.0
ApacheOpenoffice.Org3.3.0
FedoraprojectFedora15

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-1149?

CVE-2012-1149 is a vulnerability with a CVSS score of 7.5 (HIGH). Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application cr...

How severe is CVE-2012-1149?

CVE-2012-1149 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-1149?

Check the references section above for vendor advisories and patch information. Affected products include: Libreoffice Libreoffice, Debian Debian Linux, Redhat Enterprise Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server.