cbcvebase.
CVE-2012-1149
published 2012-06-21

CVE-2012-1149: Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to…

high7.5CVSS 3.1
AVNACLAuNCPIPAP
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.

Affected

19 ranges
VendorProductVersion rangeFixed in
apacheopenoffice.org
apacheopenoffice.org
debiandebian_linux
debiandebian_linux
debianlibreoffice< libreoffice 1:3.4.5-1 (bookworm)libreoffice 1:3.4.5-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
libreofficelibreoffice<= 3.5.2
libreofficelibreoffice>= 0 < 1:3.4.5-11:3.4.5-1
libreofficelibreoffice>= 0 < 1:3.4.5-11:3.4.5-1
libreofficelibreoffice>= 0 < 1:3.4.5-11:3.4.5-1
libreofficelibreoffice>= 0 < 1:3.4.5-11:3.4.5-1
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation

CVSS provenance

nvd7.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH