CVE-2007-5745: Buffer Overflow
Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted (1) Attribute and (2) Font Description records.
Other sources
Security issue found by anonymous researcher was reported via iDefense to OpenOffice.org upstream:
Synopsis: Manipulated Quattro Pro files can lead to heap overflows and arbitrary code execution
Impact: A security vulnerability with the way OpenOffice.org 2 processes Quattro Pro files may allow a remote unprivileged user who provides a OpenOffice.org document that is opened by a local user to execute arbitrary commands on the system with the privileges of the user running OpenOffice.org.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5745?
CVE-2007-5745 is classified as a high severity vulnerability due to the potential for remote code execution and denial of service.
How do I fix CVE-2007-5745?
To mitigate CVE-2007-5745, you should upgrade OpenOffice.org to version 2.4 or later.
What types of files are associated with CVE-2007-5745?
CVE-2007-5745 specifically affects Quattro Pro (QPRO) files with crafted records.
What are the potential impacts of CVE-2007-5745?
The impacts of CVE-2007-5745 include program crashes and the possibility of arbitrary code execution.
Which versions of OpenOffice are affected by CVE-2007-5745?
CVE-2007-5745 affects OpenOffice versions prior to 2.4, specifically up to 2.3.1.