Back

HIGH

libreoffice: Multiple heap-based buffer overflows in the XML manifest encryption handling code

Published Aug 6, 2012

Description

Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 6, 2012
Updated Aug 6, 2024
Reserved May 14, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Aug 1, 2012