OpenOffice "rtl_allocateMemory()" Integer Overflow Vulnerability
RISK: Medium Risk
A vulnerability has been identified in OpenOffice.org, which could be exploited by attackers to cause a denial of service or compromise an affected system. This issue is caused by an integer overflow error in the custom memory allocation function "rtl_allocateMemory()" when processing malformed data, which could be exploited by attackers to crash a vulnerable application or execute arbitrary commands by tricking a user into opening a specially crafted file.
Impact
- Remote Code Execution
System / Technologies affected
- OpenOffice.org versions 2.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to OpenOffice.org version 2.4.1 :
- http://download.openoffice.org/index.html
Vulnerability Identifier
Source
Related Link
Share with