CVE-2012-2665
published 2012-08-06CVE-2012-2665: Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote…
PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.01%
93.4th percentile
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | < 3.4.1 | 3.4.1 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libreoffice | < libreoffice 1:3.5.4-7 (bookworm) | libreoffice 1:3.5.4-7 (bookworm) |
| libreoffice | libreoffice | < 3.5.5 | 3.5.5 |
| libreoffice | libreoffice | >= 0 < 1:3.5.4-7 | 1:3.5.4-7 |
| libreoffice | libreoffice | >= 0 < 1:3.5.4-7 | 1:3.5.4-7 |
| libreoffice | libreoffice | >= 0 < 1:3.5.4-7 | 1:3.5.4-7 |
| libreoffice | libreoffice | >= 0 < 1:3.5.4-7 | 1:3.5.4-7 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_power_big_endian | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_from_rhui_6 | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenOffice.org vulnerability
vendor_ubuntu·2012-08-13
CVE-2012-2665 OpenOffice.org vulnerability
Title: OpenOffice.org vulnerability
Summary: OpenOffice.org could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that OpenOffice.org incorrectly handled certain
encryption tags in Open Document Text (.odt) files. If a user were tricked
into opening a specially crafted file, an attacker could cause
OpenOffice.org to crash or possibly execute arbitrary code with the
privileges of the user invoking the program.
Instructions: After a standard system update you need to restart OpenOffice.org to make
all the necessary changes.
Ubuntu
LibreOffice vulnerability
vendor_ubuntu·2012-08-13
CVE-2012-2665 LibreOffice vulnerability
Title: LibreOffice vulnerability
Summary: LibreOffice could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that LibreOffice incorrectly handled certain encryption
tags in Open Document Text (.odt) files. If a user were tricked into
opening a specially crafted file, an attacker could cause LibreOffice to
crash or possibly execute arbitrary code with the privileges of the user
invoking the program.
Instructions: After a standard system update you need to restart LibreOffice to make all
the necessary changes.
Red Hat
libreoffice: Multiple heap-based buffer overflows in the XML manifest encryption handling code
vendor_redhat·2012-08-01·CVSS 7.5
CVE-2012-2665 [HIGH] CWE-122 libreoffice: Multiple heap-based buffer overflows in the XML manifest encryption handling code
libreoffice: Multiple heap-based buffer overflows in the XML manifest encryption handling code
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.
Debian
CVE-2012-2665: libreoffice - Multiple heap-based buffer overflows in the XML manifest encryption tag parsing ...
vendor_debian·2012·CVSS 7.5
CVE-2012-2665 [HIGH] CVE-2012-2665: libreoffice - Multiple heap-based buffer overflows in the XML manifest encryption tag parsing ...
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.
Scope: local
bookworm: resolved (fixed in 1:3.5.4-7)
bullseye: resolved (fixed in 1:3.5.4-7)
forky: resolved (fixed in 1:3.5.4-7)
sid: resolved (fixed in 1:3.5.4-7)
trixie: resolved (fixed in 1:3.5.4-7)
GHSA
GHSA-36hh-vpg6-r82h: Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice
ghsa_unreviewed·2022-05-13
CVE-2012-2665 [HIGH] CWE-787 GHSA-36hh-vpg6-r82h: Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.
OSV
CVE-2012-2665: Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice
osv·2012-08-06·CVSS 7.5
CVE-2012-2665 [HIGH] CVE-2012-2665: Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2665 openoffice.org, libreoffice: Multiple heap-based buffer overflows in the XML manifest encryption handling code [fedora-all]
bugzilla·2012-08-01·CVSS 7.5
CVE-2012-2665 [HIGH] CVE-2012-2665 openoffice.org, libreoffice: Multiple heap-based buffer overflows in the XML manifest encryption handling code [fedora-all]
CVE-2012-2665 openoffice.org, libreoffice: Multiple heap-based buffer overflows in the XML manifest encryption handling code [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission lin
Bugzilla
CVE-2012-2665 openoffice.org, libreoffice: Multiple heap-based buffer overflows in the XML manifest encryption handling code
bugzilla·2012-05-29·CVSS 7.5
CVE-2012-2665 [HIGH] CVE-2012-2665 openoffice.org, libreoffice: Multiple heap-based buffer overflows in the XML manifest encryption handling code
CVE-2012-2665 openoffice.org, libreoffice: Multiple heap-based buffer overflows in the XML manifest encryption handling code
Multiple heap-based buffer overflow flaws were found in the XML manifest encryption handling code of OpenOffice.org and LibreOffice:
1) Previously it was not checked if the particular tag was contained within expected parent tag, leading to possibility of child tag handler being able to write its data into different (than expected) parent handler sequence, leading to heap buffer overflow,
2) also a fixed size sequence was allocated to record properties of a particular XML tag, associated with XML element. By duplicating certain tags in XML manifest it was possible to write past the heap-based buffer bounds,
3) yet, the Base64 decoder implementation incorrectly as
http://rhn.redhat.com/errata/RHSA-2012-1135.htmlhttp://secunia.com/advisories/50142http://secunia.com/advisories/50146http://secunia.com/advisories/50692http://secunia.com/advisories/60799http://security.gentoo.org/glsa/glsa-201209-05.xmlhttp://www.debian.org/security/2012/dsa-2520http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.libreoffice.org/about-us/security/advisories/cve-2012-2665/http://www.pre-cert.de/advisories/PRE-SA-2012-05.txthttp://www.securityfocus.com/bid/54769http://www.securitytracker.com/id?1027331http://www.securitytracker.com/id?1027332http://www.ubuntu.com/usn/USN-1536-1http://www.ubuntu.com/usn/USN-1537-1https://bugzilla.redhat.com/show_bug.cgi?id=826077http://rhn.redhat.com/errata/RHSA-2012-1135.htmlhttp://secunia.com/advisories/50142http://secunia.com/advisories/50146http://secunia.com/advisories/50692http://secunia.com/advisories/60799http://security.gentoo.org/glsa/glsa-201209-05.xmlhttp://www.debian.org/security/2012/dsa-2520http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.libreoffice.org/about-us/security/advisories/cve-2012-2665/http://www.pre-cert.de/advisories/PRE-SA-2012-05.txthttp://www.securityfocus.com/bid/54769http://www.securitytracker.com/id?1027331http://www.securitytracker.com/id?1027332http://www.ubuntu.com/usn/USN-1536-1http://www.ubuntu.com/usn/USN-1537-1https://bugzilla.redhat.com/show_bug.cgi?id=826077
2012-08-06
Published