CVE-2014-3693
published 2014-11-07CVE-2014-3693: Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a…
PriorityP344high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.96%
91.2th percentile
Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libreoffice | < libreoffice 1:4.3.3~rc2~git20141011-1 (bookworm) | libreoffice 1:4.3.3~rc2~git20141011-1 (bookworm) |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | >= 0 < 1:4.3.3~rc2~git20141011-1 | 1:4.3.3~rc2~git20141011-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libreoffice: Use-After-Free in socket manager of Impress Remote
vendor_redhat·2014-11-05·CVSS 7.5
CVE-2014-3693 [HIGH] CWE-416 libreoffice: Use-After-Free in socket manager of Impress Remote
libreoffice: Use-After-Free in socket manager of Impress Remote
Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599.
A use-after-free flaw was found in the "Remote Control" capabilities of the LibreOffice Impress application. An attacker could use this flaw to remotely execute code with the permissions of the user running LibreOffice Impress.
Package: libreoffice (Red Hat Enterprise Linux 6) - Will not fix
Ubuntu
LibreOffice vulnerability
vendor_ubuntu·2014-11-05
CVE-2014-3693 LibreOffice vulnerability
Title: LibreOffice vulnerability
Summary: LibreOffice could be made to crash or run programs if it received specially
crafted network traffic.
It was discovered that LibreOffice incorrectly handled the Impress remote
control port. An attacker could possibly use this issue to cause Impress to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart LibreOffice to
make all the necessary changes.
Debian
CVE-2014-3693: libreoffice - Use-after-free vulnerability in the socket manager of Impress Remote in LibreOff...
vendor_debian·2014·CVSS 7.5
CVE-2014-3693 [HIGH] CVE-2014-3693: libreoffice - Use-after-free vulnerability in the socket manager of Impress Remote in LibreOff...
Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599.
Scope: local
bookworm: resolved (fixed in 1:4.3.3~rc2~git20141011-1)
bullseye: resolved (fixed in 1:4.3.3~rc2~git20141011-1)
forky: resolved (fixed in 1:4.3.3~rc2~git20141011-1)
sid: resolved (fixed in 1:4.3.3~rc2~git20141011-1)
trixie: resolved (fixed in 1:4.3.3~rc2~git20141011-1)
GHSA
GHSA-2cc9-9pjp-x968: Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4
ghsa_unreviewed·2022-05-14
CVE-2014-3693 [HIGH] GHSA-2cc9-9pjp-x968: Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4
Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599.
OSV
CVE-2014-3693: Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4
osv·2014-11-07·CVSS 7.5
CVE-2014-3693 [HIGH] CVE-2014-3693: Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4
Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3693 libreoffice: Use-After-Free in socket manager of Impress Remote [fedora-all]
bugzilla·2014-11-24·CVSS 7.5
CVE-2014-3693 [HIGH] CVE-2014-3693 libreoffice: Use-After-Free in socket manager of Impress Remote [fedora-all]
CVE-2014-3693 libreoffice: Use-After-Free in socket manager of Impress Remote [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2014-3693 libreoffice: Use-After-Free in socket manager of Impress Remote
bugzilla·2014-11-17·CVSS 7.5
CVE-2014-3693 [HIGH] CVE-2014-3693 libreoffice: Use-After-Free in socket manager of Impress Remote
CVE-2014-3693 libreoffice: Use-After-Free in socket manager of Impress Remote
As per upstream libreoffice advisory:
In LibreOffice 4.0.0 and later, a new feature was added for remote control capabilities in Impress. Users can run a smart phone
application to communicate with Impress over a custom protocol to switch slides and the like. By default whenever Impress is started, it immediately began listening on TCP port 1599 on all interfaces.
But there was a use after free bug in the code managing that port leaving LibreOffice vulnerable to external attackers with access to that port where those external attackers could cause the deleted port manager to continue to process attacker supplied data.
All users are recommended to upgrade to LibreOffice 4.2.7 or 4.3.3.
The impress remote can
http://lists.opensuse.org/opensuse-updates/2014-11/msg00049.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0377.htmlhttp://secunia.com/advisories/62111http://secunia.com/advisories/62132http://secunia.com/advisories/62396http://www.securityfocus.com/bid/71351http://www.ubuntu.com/usn/USN-2398-1https://security.gentoo.org/glsa/201603-05https://www.libreoffice.org/about-us/security/advisories/CVE-2014-3693/http://lists.opensuse.org/opensuse-updates/2014-11/msg00049.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0377.htmlhttp://secunia.com/advisories/62111http://secunia.com/advisories/62132http://secunia.com/advisories/62396http://www.securityfocus.com/bid/71351http://www.ubuntu.com/usn/USN-2398-1https://security.gentoo.org/glsa/201603-05https://www.libreoffice.org/about-us/security/advisories/CVE-2014-3693/
2014-11-07
Published