CVE-2014-9093
published 2014-11-26CVE-2014-9093: LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.14%
89.7th percentile
LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libreoffice | < libreoffice 1:4.3.3-2 (bookworm) | libreoffice 1:4.3.3-2 (bookworm) |
| fedoraproject | fedora | — | — |
| libreoffice | libreoffice | <= 4.3.4 | — |
| libreoffice | libreoffice | >= 0 < 1:4.3.3-2 | 1:4.3.3-2 |
| libreoffice | libreoffice | >= 0 < 1:4.3.3-2 | 1:4.3.3-2 |
| libreoffice | libreoffice | >= 0 < 1:4.3.3-2 | 1:4.3.3-2 |
| libreoffice | libreoffice | >= 0 < 1:4.3.3-2 | 1:4.3.3-2 |
| libreoffice | libreoffice | >= 0 < 1:4.2.8-0ubuntu2 | 1:4.2.8-0ubuntu2 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LibreOffice vulnerabilities
vendor_ubuntu·2015-04-27·CVSS 7.5
CVE-2014-9093 [HIGH] LibreOffice vulnerabilities
Title: LibreOffice vulnerabilities
Summary: LibreOffice could be made to crash or run programs as your login if it
opened a specially crafted file.
Alexander Cherepanov discovered that LibreOffice incorrectly handled
certain RTF files. If a user were tricked into opening a specially crafted
RTF document, a remote attacker could cause LibreOffice to crash, and
possibly execute arbitrary code. (CVE-2014-9093)
It was discovered that LibreOffice incorrectly handled certain HWP files.
If a user were tricked into opening a specially crafted HWP document, a
remote attacker could cause LibreOffice to crash, and possibly execute
arbitrary code. (CVE-2015-1774)
Instructions: After a standard system update you need to restart LibreOffice to make all
the necessary changes.
Red Hat
libreoffice: crash importing malformed .rtf
vendor_redhat·2014-11-19·CVSS 7.5
CVE-2014-9093 [HIGH] libreoffice: crash importing malformed .rtf
libreoffice: crash importing malformed .rtf
LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file.
Package: libreoffice (Red Hat Enterprise Linux 6) - Will not fix
Package: libreoffice (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2014-9093: libreoffice - LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (i...
vendor_debian·2014·CVSS 7.5
CVE-2014-9093 [HIGH] CVE-2014-9093: libreoffice - LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (i...
LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file.
Scope: local
bookworm: resolved (fixed in 1:4.3.3-2)
bullseye: resolved (fixed in 1:4.3.3-2)
forky: resolved (fixed in 1:4.3.3-2)
sid: resolved (fixed in 1:4.3.3-2)
trixie: resolved (fixed in 1:4.3.3-2)
GHSA
GHSA-75f2-6p94-94mp: LibreOffice before 4
ghsa_unreviewed·2022-05-17
CVE-2014-9093 [HIGH] CWE-20 GHSA-75f2-6p94-94mp: LibreOffice before 4
LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file.
OSV
libreoffice vulnerabilities
osv·2015-04-27·CVSS 7.5
CVE-2014-9093 [HIGH] libreoffice vulnerabilities
libreoffice vulnerabilities
Alexander Cherepanov discovered that LibreOffice incorrectly handled
certain RTF files. If a user were tricked into opening a specially crafted
RTF document, a remote attacker could cause LibreOffice to crash, and
possibly execute arbitrary code. (CVE-2014-9093)
It was discovered that LibreOffice incorrectly handled certain HWP files.
If a user were tricked into opening a specially crafted HWP document, a
remote attacker could cause LibreOffice to crash, and possibly execute
arbitrary code. (CVE-2015-1774)
OSV
CVE-2014-9093: LibreOffice before 4
osv·2014-11-26·CVSS 7.5
CVE-2014-9093 [HIGH] CVE-2014-9093: LibreOffice before 4
LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2014-November/144836.htmlhttp://www.debian.org/security/2015/dsa-3163http://www.openwall.com/lists/oss-security/2014/11/19/3http://www.openwall.com/lists/oss-security/2014/11/26/7http://www.ubuntu.com/usn/USN-2578-1https://bugs.freedesktop.org/show_bug.cgi?id=86449https://security.gentoo.org/glsa/201603-05http://lists.fedoraproject.org/pipermail/package-announce/2014-November/144836.htmlhttp://www.debian.org/security/2015/dsa-3163http://www.openwall.com/lists/oss-security/2014/11/19/3http://www.openwall.com/lists/oss-security/2014/11/26/7http://www.ubuntu.com/usn/USN-2578-1https://bugs.freedesktop.org/show_bug.cgi?id=86449https://security.gentoo.org/glsa/201603-05
2014-11-26
Published