CVE-2016-0794
published 2016-02-18CVE-2016-0794: The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact…
PriorityP434high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
2.83%
85.1th percentile
The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libreoffice | < libreoffice 1:5.0.5~rc1-1 (bookworm) | libreoffice 1:5.0.5~rc1-1 (bookworm) |
| libreoffice | libreoffice | <= 5.0.3 | — |
| libreoffice | libreoffice | >= 0 < 1:5.0.5~rc1-1 | 1:5.0.5~rc1-1 |
| libreoffice | libreoffice | >= 0 < 1:5.0.5~rc1-1 | 1:5.0.5~rc1-1 |
| libreoffice | libreoffice | >= 0 < 1:5.0.5~rc1-1 | 1:5.0.5~rc1-1 |
| libreoffice | libreoffice | >= 0 < 1:5.0.5~rc1-1 | 1:5.0.5~rc1-1 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h7v3-vhmj-p7g5: The lwp filter in LibreOffice before 5
ghsa_unreviewed·2022-05-14
CVE-2016-0794 [HIGH] CWE-119 GHSA-h7v3-vhmj-p7g5: The lwp filter in LibreOffice before 5
The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.
OSV
CVE-2016-0794: The lwp filter in LibreOffice before 5
osv·2016-02-18·CVSS 7.8
CVE-2016-0794 [HIGH] CVE-2016-0794: The lwp filter in LibreOffice before 5
The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.
Ubuntu
LibreOffice vulnerabilities
vendor_ubuntu·2016-02-16
CVE-2016-0794 LibreOffice vulnerabilities
Title: LibreOffice vulnerabilities
Summary: LibreOffice could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that LibreOffice incorrectly handled LWP document files.
If a user were tricked into opening a specially crafted LWP document, a
remote attacker could cause LibreOffice to crash, and possibly execute
arbitrary code.
Instructions: After a standard system update you need to restart LibreOffice to make all
the necessary changes.
Red Hat
libreoffice: Multiple out-of-bounds overflows in lwp filter
vendor_redhat·2016-02-15·CVSS 7.8
CVE-2016-0794 [HIGH] CWE-119 libreoffice: Multiple out-of-bounds overflows in lwp filter
libreoffice: Multiple out-of-bounds overflows in lwp filter
The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.
Multiple flaws were found in the Lotus Word Pro (LWP) document format parser in LibreOffice. By tricking a user into opening a specially crafted LWP document, an attacker could possibly use this flaw to execute arbitrary code with the privileges of the user opening the file.
Package: openoffice.org (Red Hat Enterprise Linux 5) - Not affected
Package: libreoffice (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2016-0794: libreoffice - The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a de...
vendor_debian·2016·CVSS 7.8
CVE-2016-0794 [HIGH] CVE-2016-0794: libreoffice - The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a de...
The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.
Scope: local
bookworm: resolved (fixed in 1:5.0.5~rc1-1)
bullseye: resolved (fixed in 1:5.0.5~rc1-1)
forky: resolved (fixed in 1:5.0.5~rc1-1)
sid: resolved (fixed in 1:5.0.5~rc1-1)
trixie: resolved (fixed in 1:5.0.5~rc1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4049 quagga: denial of service vulnerability in BGP routing daemon
bugzilla·2016-04-28·CVSS 7.5
CVE-2016-4049 [HIGH] CVE-2016-4049 quagga: denial of service vulnerability in BGP routing daemon
CVE-2016-4049 quagga: denial of service vulnerability in BGP routing daemon
A denial of service flaw was found in the Quagga BGP routing daemon (bgpd). Under certain circumstances, an attacker could use a crafted packet to crash the bgpd service.
External References:
http://openwall.com/lists/oss-security/2016/04/27/7
Discussion:
Created quagga tracking bugs for this issue:
Affects: fedora-all [bug 1331373]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2017:0794 https://rhn.redhat.com/errata/RHSA-2017-0794.html
Bugzilla
CVE-2016-0794 CVE-2016-0795 libreoffice: Multiple out-of-bounds overflows in lwp filter [fedora-all]
bugzilla·2016-02-17·CVSS 7.8
CVE-2016-0794 [HIGH] CVE-2016-0794 CVE-2016-0795 libreoffice: Multiple out-of-bounds overflows in lwp filter [fedora-all]
CVE-2016-0794 CVE-2016-0795 libreoffice: Multiple out-of-bounds overflows in lwp filter [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2016-0794 CVE-2016-0795 libreoffice: Multiple out-of-bounds overflows in lwp filter
bugzilla·2016-02-11·CVSS 7.8
CVE-2016-0794 [HIGH] CVE-2016-0794 CVE-2016-0795 libreoffice: Multiple out-of-bounds overflows in lwp filter
CVE-2016-0794 CVE-2016-0795 libreoffice: Multiple out-of-bounds overflows in lwp filter
Multiple out-of-bounds access vulnerabilities were found in lwp filter in libreoffice 5.0.5 and 5.0.4.
5.0.5
https://github.com/LibreOffice/core/commit/e0dca588239c0902ea90fcdc2b6d0ee2b1525ec2
5.0.4
https://github.com/LibreOffice/core/commit/539fda2d5527742023eb7ce537113639ed1c1982
https://github.com/LibreOffice/core/commit/64070e8f3ec976f48e233064795eff756b6d5146
https://github.com/LibreOffice/core/commit/21e0778bcbb2d90e471f59166e74c00aa044a1df
https://github.com/LibreOffice/core/commit/85a2cd37fc60cd53a892b27a18d4b5272988361c
Discussion:
Created libreoffice tracking bugs for this issue:
Affects: fedora-all [bug 1309207]
---
Public via:
http://www.ubuntu.com/usn/usn-2899-1/
---
LibreOffic
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178036.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00110.htmlhttp://lists.opensuse.org/opensuse-updates/2016-07/msg00050.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2579.htmlhttp://www.debian.org/security/2016/dsa-3482http://www.securitytracker.com/id/1035022http://www.ubuntu.com/usn/USN-2899-1https://www.libreoffice.org/about-us/security/advisories/cve-2016-0794/https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1220https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1221https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1222http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178036.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00110.htmlhttp://lists.opensuse.org/opensuse-updates/2016-07/msg00050.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2579.htmlhttp://www.debian.org/security/2016/dsa-3482http://www.securitytracker.com/id/1035022http://www.ubuntu.com/usn/USN-2899-1https://www.libreoffice.org/about-us/security/advisories/cve-2016-0794/https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1220https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1221https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1222
2016-02-18
Published