CVE-2007-2834
published 2007-09-18CVE-2007-2834: Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to…
PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
11.32%
95.5th percentile
Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | < 2.3.0 | 2.3.0 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| sun | staroffice | — | — |
| sun | staroffice | — | — |
| sun | staroffice | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9vj3-8mhr-2vxc: Integer overflow in the TIFF parser in OpenOffice
ghsa_unreviewed·2022-05-01
CVE-2007-2834 [HIGH] CWE-190 GHSA-9vj3-8mhr-2vxc: Integer overflow in the TIFF parser in OpenOffice
Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.
Ubuntu
OpenOffice.org vulnerability
vendor_ubuntu·2007-10-04
CVE-2007-2834 OpenOffice.org vulnerability
Title: OpenOffice.org vulnerability
Summary: OpenOffice.org vulnerability
An integer overflow was discovered in the TIFF handling code in OpenOffice.
If a user were tricked into loading a malicious TIFF image, a remote attacker
could execute arbitrary code with user privileges.
Instructions: After a standard system upgrade you need to restart OpenOffice to effect
the necessary changes.
Red Hat
openoffice.org TIFF parsing heap overflow
vendor_redhat·2007-09-17·CVSS 9.3
CVE-2007-2834 [CRITICAL] openoffice.org TIFF parsing heap overflow
openoffice.org TIFF parsing heap overflow
Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-2834 openoffice.org TIFF parsing heap overflow [F7]
bugzilla·2007-09-17·CVSS 9.3
CVE-2007-2834 [CRITICAL] CVE-2007-2834 openoffice.org TIFF parsing heap overflow [F7]
CVE-2007-2834 openoffice.org TIFF parsing heap overflow [F7]
F7 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
openoffice.org-2.2.1-18.2.fc7 has been submitted for this, but is pending being
pushed by security team
i.e.
https://admin.fedoraproject.org/updates/pending/F7/openoffice.org-2.2.1-18.2.fc7
Bugzilla
CVE-2007-2834 openoffice.org TIFF parsing heap overflow [FC6]
bugzilla·2007-09-17·CVSS 9.3
CVE-2007-2834 [CRITICAL] CVE-2007-2834 openoffice.org TIFF parsing heap overflow [FC6]
CVE-2007-2834 openoffice.org TIFF parsing heap overflow [FC6]
FC6 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
jnavrati pushed this on 18th September: i.e. openoffice.org-2.0.4-5.5.24
Bugzilla
CVE-2007-2834 openoffice.org TIFF parsing heap overflow
bugzilla·2007-08-13·CVSS 9.3
CVE-2007-2834 [CRITICAL] CVE-2007-2834 openoffice.org TIFF parsing heap overflow
CVE-2007-2834 openoffice.org TIFF parsing heap overflow
An anonymous researcher reported to iDefense a heap overflow in TIFF parsing in
OpenOffice.org. If a victim opens a carefully crafted document containing a
malicious TIFF file it could lead to arbitrary code execution.
Embargo set to 20070904
Discussion:
Created attachment 161195
proposed patch
---
Vulnerability was publicly announced by OpenOffice.org project and fixed in
OpenOffice.org 2.3:
http://www.openoffice.org/security/cves/CVE-2007-2834.html
Removing embargo.
---
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2007-0848.html
Fedora:
https://admin.fedoraproject.org/updates/F7/FEDORA-2007-2372
http://bugs.gentoo.org/show_bug.cgi?id=192818http://fedoranews.org/updates/FEDORA-2007-237.shtmlhttp://fedoranews.org/updates/FEDORA-2007-700.shtmlhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=593http://lists.opensuse.org/opensuse-security-announce/2007-09/msg00002.htmlhttp://secunia.com/advisories/26816http://secunia.com/advisories/26817http://secunia.com/advisories/26839http://secunia.com/advisories/26844http://secunia.com/advisories/26855http://secunia.com/advisories/26861http://secunia.com/advisories/26891http://secunia.com/advisories/26903http://secunia.com/advisories/26912http://secunia.com/advisories/27077http://secunia.com/advisories/27087http://secunia.com/advisories/27370http://security.gentoo.org/glsa/glsa-200710-24.xmlhttp://securitytracker.com/id?1018702http://sunsolve.sun.com/search/document.do?assetkey=1-26-102994-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200190-1http://www.debian.org/security/2007/dsa-1375http://www.mandriva.com/security/advisories?name=MDKSA-2007:186http://www.openoffice.org/security/cves/CVE-2007-2834.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0848.htmlhttp://www.securityfocus.com/archive/1/479965/100/0/threadedhttp://www.securityfocus.com/bid/25690http://www.ubuntu.com/usn/usn-524-1http://www.vupen.com/english/advisories/2007/3184http://www.vupen.com/english/advisories/2007/3262https://exchange.xforce.ibmcloud.com/vulnerabilities/36656https://issues.rpath.com/browse/RPL-1740https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9967http://bugs.gentoo.org/show_bug.cgi?id=192818http://fedoranews.org/updates/FEDORA-2007-237.shtmlhttp://fedoranews.org/updates/FEDORA-2007-700.shtmlhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=593http://lists.opensuse.org/opensuse-security-announce/2007-09/msg00002.htmlhttp://secunia.com/advisories/26816http://secunia.com/advisories/26817http://secunia.com/advisories/26839http://secunia.com/advisories/26844http://secunia.com/advisories/26855http://secunia.com/advisories/26861http://secunia.com/advisories/26891http://secunia.com/advisories/26903http://secunia.com/advisories/26912http://secunia.com/advisories/27077http://secunia.com/advisories/27087http://secunia.com/advisories/27370http://security.gentoo.org/glsa/glsa-200710-24.xmlhttp://securitytracker.com/id?1018702http://sunsolve.sun.com/search/document.do?assetkey=1-26-102994-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200190-1http://www.debian.org/security/2007/dsa-1375http://www.mandriva.com/security/advisories?name=MDKSA-2007:186http://www.openoffice.org/security/cves/CVE-2007-2834.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0848.htmlhttp://www.securityfocus.com/archive/1/479965/100/0/threadedhttp://www.securityfocus.com/bid/25690http://www.ubuntu.com/usn/usn-524-1http://www.vupen.com/english/advisories/2007/3184http://www.vupen.com/english/advisories/2007/3262https://exchange.xforce.ibmcloud.com/vulnerabilities/36656https://issues.rpath.com/browse/RPL-1740https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9967
2007-09-18
Published