CVE-2016-0795
published 2016-02-18CVE-2016-0795: LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted…
PriorityP433high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
2.78%
84.9th percentile
LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (lwp) document.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libreoffice | < libreoffice 1:5.0.5~rc1-1 (bookworm) | libreoffice 1:5.0.5~rc1-1 (bookworm) |
| libreoffice | libreoffice | <= 5.0.4 | — |
| libreoffice | libreoffice | >= 0 < 1:5.0.5~rc1-1 | 1:5.0.5~rc1-1 |
| libreoffice | libreoffice | >= 0 < 1:5.0.5~rc1-1 | 1:5.0.5~rc1-1 |
| libreoffice | libreoffice | >= 0 < 1:5.0.5~rc1-1 | 1:5.0.5~rc1-1 |
| libreoffice | libreoffice | >= 0 < 1:5.0.5~rc1-1 | 1:5.0.5~rc1-1 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LibreOffice vulnerabilities
vendor_ubuntu·2016-02-16
CVE-2016-0794 LibreOffice vulnerabilities
Title: LibreOffice vulnerabilities
Summary: LibreOffice could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that LibreOffice incorrectly handled LWP document files.
If a user were tricked into opening a specially crafted LWP document, a
remote attacker could cause LibreOffice to crash, and possibly execute
arbitrary code.
Instructions: After a standard system update you need to restart LibreOffice to make all
the necessary changes.
Red Hat
libreoffice: Multiple out-of-bounds overflows in lwp filter
vendor_redhat·2016-02-15·CVSS 7.8
CVE-2016-0795 [HIGH] CWE-119 libreoffice: Multiple out-of-bounds overflows in lwp filter
libreoffice: Multiple out-of-bounds overflows in lwp filter
LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (lwp) document.
Multiple flaws were found in the Lotus Word Pro (LWP) document format parser in LibreOffice. By tricking a user into opening a specially crafted LWP document, an attacker could possibly use this flaw to execute arbitrary code with the privileges of the user opening the file.
Package: openoffice.org (Red Hat Enterprise Linux 5) - Not affected
Package: libreoffice (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2016-0795: libreoffice - LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (m...
vendor_debian·2016·CVSS 7.8
CVE-2016-0795 [HIGH] CVE-2016-0795: libreoffice - LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (m...
LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (lwp) document.
Scope: local
bookworm: resolved (fixed in 1:5.0.5~rc1-1)
bullseye: resolved (fixed in 1:5.0.5~rc1-1)
forky: resolved (fixed in 1:5.0.5~rc1-1)
sid: resolved (fixed in 1:5.0.5~rc1-1)
trixie: resolved (fixed in 1:5.0.5~rc1-1)
GHSA
GHSA-8w74-7x35-c5pw: LibreOffice before 5
ghsa_unreviewed·2022-05-14
CVE-2016-0795 [HIGH] CWE-119 GHSA-8w74-7x35-c5pw: LibreOffice before 5
LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (lwp) document.
OSV
CVE-2016-0795: LibreOffice before 5
osv·2016-02-18·CVSS 7.8
CVE-2016-0795 [HIGH] CVE-2016-0795: LibreOffice before 5
LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (lwp) document.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-0794 CVE-2016-0795 libreoffice: Multiple out-of-bounds overflows in lwp filter [fedora-all]
bugzilla·2016-02-17·CVSS 7.8
CVE-2016-0794 [HIGH] CVE-2016-0794 CVE-2016-0795 libreoffice: Multiple out-of-bounds overflows in lwp filter [fedora-all]
CVE-2016-0794 CVE-2016-0795 libreoffice: Multiple out-of-bounds overflows in lwp filter [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2016-0794 CVE-2016-0795 libreoffice: Multiple out-of-bounds overflows in lwp filter
bugzilla·2016-02-11·CVSS 7.8
CVE-2016-0794 [HIGH] CVE-2016-0794 CVE-2016-0795 libreoffice: Multiple out-of-bounds overflows in lwp filter
CVE-2016-0794 CVE-2016-0795 libreoffice: Multiple out-of-bounds overflows in lwp filter
Multiple out-of-bounds access vulnerabilities were found in lwp filter in libreoffice 5.0.5 and 5.0.4.
5.0.5
https://github.com/LibreOffice/core/commit/e0dca588239c0902ea90fcdc2b6d0ee2b1525ec2
5.0.4
https://github.com/LibreOffice/core/commit/539fda2d5527742023eb7ce537113639ed1c1982
https://github.com/LibreOffice/core/commit/64070e8f3ec976f48e233064795eff756b6d5146
https://github.com/LibreOffice/core/commit/21e0778bcbb2d90e471f59166e74c00aa044a1df
https://github.com/LibreOffice/core/commit/85a2cd37fc60cd53a892b27a18d4b5272988361c
Discussion:
Created libreoffice tracking bugs for this issue:
Affects: fedora-all [bug 1309207]
---
Public via:
http://www.ubuntu.com/usn/usn-2899-1/
---
LibreOffic
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178036.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00110.htmlhttp://lists.opensuse.org/opensuse-updates/2016-07/msg00050.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2579.htmlhttp://www.debian.org/security/2016/dsa-3482http://www.securitytracker.com/id/1035022http://www.ubuntu.com/usn/USN-2899-1https://www.libreoffice.org/about-us/security/advisories/cve-2016-0795/https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1223http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178036.htmlhttp://lists.opensuse.org/opensuse-updates/2016-05/msg00110.htmlhttp://lists.opensuse.org/opensuse-updates/2016-07/msg00050.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2579.htmlhttp://www.debian.org/security/2016/dsa-3482http://www.securitytracker.com/id/1035022http://www.ubuntu.com/usn/USN-2899-1https://www.libreoffice.org/about-us/security/advisories/cve-2016-0795/https://www.verisign.com/en_US/security-services/security-intelligence/vulnerability-reports/articles/index.xhtml?id=1223
2016-02-18
Published