CVE-2012-4233
published 2012-11-19CVE-2012-4233: LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo), allows remote attackers to cause a denial of service (NULL pointer…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.48%
87.9th percentile
LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo), allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted (1) odt file to vcllo.dll, (2) ODG (Drawing document) file to svxcorelo.dll, (3) PolyPolygon record in a .wmf (Window Meta File) file embedded in a ppt (PowerPoint) file to tllo.dll, or (4) xls (Excel) file to scfiltlo.dll.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libreoffice | < libreoffice 1:3.5.4+dfsg-3 (bookworm) | libreoffice 1:3.5.4+dfsg-3 (bookworm) |
| libreoffice | libreoffice | <= 3.6 | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | >= 0 < 1:3.5.4+dfsg-3 | 1:3.5.4+dfsg-3 |
| libreoffice | libreoffice | >= 0 < 1:3.5.4+dfsg-3 | 1:3.5.4+dfsg-3 |
| libreoffice | libreoffice | >= 0 < 1:3.5.4+dfsg-3 | 1:3.5.4+dfsg-3 |
| libreoffice | libreoffice | >= 0 < 1:3.5.4+dfsg-3 | 1:3.5.4+dfsg-3 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libreoffice: multiple null pointer dereference flaws
vendor_redhat·2012-10-31·CVSS 4.3
CVE-2012-4233 [MEDIUM] CWE-476 libreoffice: multiple null pointer dereference flaws
libreoffice: multiple null pointer dereference flaws
LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo), allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted (1) odt file to vcllo.dll, (2) ODG (Drawing document) file to svxcorelo.dll, (3) PolyPolygon record in a .wmf (Window Meta File) file embedded in a ppt (PowerPoint) file to tllo.dll, or (4) xls (Excel) file to scfiltlo.dll.
Statement: Red Hat Security Response Team does not consider a user assisted denial of service (and potential crash) of end user application, such as tools from LibreOffice productivity suite, to be a security issue.
Package: openoffice.org (Red Hat Enterprise Linux 5) - Will not fix
Package: libreoffice (Red Hat Enterprise Linux 6) - Will n
Debian
CVE-2012-4233: libreoffice - LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo...
vendor_debian·2012·CVSS 4.3
CVE-2012-4233 [MEDIUM] CVE-2012-4233: libreoffice - LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo...
LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo), allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted (1) odt file to vcllo.dll, (2) ODG (Drawing document) file to svxcorelo.dll, (3) PolyPolygon record in a .wmf (Window Meta File) file embedded in a ppt (PowerPoint) file to tllo.dll, or (4) xls (Excel) file to scfiltlo.dll.
Scope: local
bookworm: resolved (fixed in 1:3.5.4+dfsg-3)
bullseye: resolved (fixed in 1:3.5.4+dfsg-3)
forky: resolved (fixed in 1:3.5.4+dfsg-3)
sid: resolved (fixed in 1:3.5.4+dfsg-3)
trixie: resolved (fixed in 1:3.5.4+dfsg-3)
GHSA
GHSA-238c-g57x-fg8c: LibreOffice 3
ghsa_unreviewed·2022-05-17
CVE-2012-4233 [MEDIUM] GHSA-238c-g57x-fg8c: LibreOffice 3
LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo), allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted (1) odt file to vcllo.dll, (2) ODG (Drawing document) file to svxcorelo.dll, (3) PolyPolygon record in a .wmf (Window Meta File) file embedded in a ppt (PowerPoint) file to tllo.dll, or (4) xls (Excel) file to scfiltlo.dll.
OSV
CVE-2012-4233: LibreOffice 3
osv·2012-11-19·CVSS 4.3
CVE-2012-4233 [MEDIUM] CVE-2012-4233: LibreOffice 3
LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo), allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted (1) odt file to vcllo.dll, (2) ODG (Drawing document) file to svxcorelo.dll, (3) PolyPolygon record in a .wmf (Window Meta File) file embedded in a ppt (PowerPoint) file to tllo.dll, or (4) xls (Excel) file to scfiltlo.dll.
No detection rules found.
No public exploits indexed.
http://cgit.freedesktop.org/libreoffice/binfilter/commit/?h=libreoffice-3-5-7&id=7e22ee55ffc9743692f3ddb93e59dd4427029c5bhttp://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-3-5-7&id=44bc6b5cac723b52df40fbef026e99b7119d8a69http://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-3-5-7&id=6789ec4c1a9c6af84bd62e650a03226a46365d97http://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-3-5-7&id=8ca9fb05c9967f11670d045886438ddfa3ac02a7http://lists.opensuse.org/opensuse-updates/2012-11/msg00039.htmlhttp://lists.opensuse.org/opensuse-updates/2012-12/msg00075.htmlhttp://www.debian.org/security/2012/dsa-2570http://www.libreoffice.org/advisories/cve-2012-4233/http://www.openwall.com/lists/oss-security/2012/11/02/2http://www.securityfocus.com/bid/56352https://exchange.xforce.ibmcloud.com/vulnerabilities/79728https://exchange.xforce.ibmcloud.com/vulnerabilities/79730https://exchange.xforce.ibmcloud.com/vulnerabilities/79731https://exchange.xforce.ibmcloud.com/vulnerabilities/79732https://www.htbridge.com/advisory/HTB23106http://cgit.freedesktop.org/libreoffice/binfilter/commit/?h=libreoffice-3-5-7&id=7e22ee55ffc9743692f3ddb93e59dd4427029c5bhttp://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-3-5-7&id=44bc6b5cac723b52df40fbef026e99b7119d8a69http://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-3-5-7&id=6789ec4c1a9c6af84bd62e650a03226a46365d97http://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-3-5-7&id=8ca9fb05c9967f11670d045886438ddfa3ac02a7http://lists.opensuse.org/opensuse-updates/2012-11/msg00039.htmlhttp://lists.opensuse.org/opensuse-updates/2012-12/msg00075.htmlhttp://www.debian.org/security/2012/dsa-2570http://www.libreoffice.org/advisories/cve-2012-4233/http://www.openwall.com/lists/oss-security/2012/11/02/2http://www.securityfocus.com/bid/56352https://exchange.xforce.ibmcloud.com/vulnerabilities/79728https://exchange.xforce.ibmcloud.com/vulnerabilities/79730https://exchange.xforce.ibmcloud.com/vulnerabilities/79731https://exchange.xforce.ibmcloud.com/vulnerabilities/79732https://www.htbridge.com/advisory/HTB23106
2012-11-19
Published