CVE-2007-5746: Buffer Overflow
Published Apr 17, 2008
·Updated
Integer overflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an EMF file with a crafted EMRSTRETCHBLT record, which triggers a heap-based buffer overflow.
Affected Software
6 affected components
OpenOffice OpenOffice.org=2.3.1
OpenOffice OpenOffice.org=2.2.1
OpenOffice OpenOffice.org=2.1
OpenOffice OpenOffice.org=2.2
OpenOffice OpenOffice.org=2.3
OpenOffice OpenOffice.org=2.0.3
Event History
Apr 17, 2008
CVE Published
07:05 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5746?
CVE-2007-5746 has a moderate severity rating due to its potential to cause a denial of service and possible arbitrary code execution.
2
How do I fix CVE-2007-5746?
To fix CVE-2007-5746, upgrade to a patched version of OpenOffice.org that is above 2.4.
3
What types of attacks can CVE-2007-5746 enable?
CVE-2007-5746 can enable denial of service attacks and potentially lead to arbitrary code execution.
4
Which versions of OpenOffice.org are affected by CVE-2007-5746?
CVE-2007-5746 affects all versions of OpenOffice.org prior to 2.4.
5
What kind of file can trigger CVE-2007-5746?
An EMF file with a crafted EMR_STRETCHBLT record can trigger CVE-2007-5746.