CVE-2008-0320: Buffer Overflow
Published Apr 17, 2008
·Updated
Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream.
Affected Software
6 affected components
OpenOffice OpenOffice.org=2.2.1
OpenOffice OpenOffice.org=2.1
OpenOffice OpenOffice.org<=2.3.1
OpenOffice OpenOffice.org=2.2
OpenOffice OpenOffice.org=2.3
OpenOffice OpenOffice.org=2.0.3
Event History
Apr 17, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0320?
CVE-2008-0320 is considered critical because it allows remote attackers to potentially execute arbitrary code.
2
How do I fix CVE-2008-0320?
To fix CVE-2008-0320, you should upgrade OpenOffice.org to version 2.4 or later.
3
Which versions of OpenOffice.org are affected by CVE-2008-0320?
CVE-2008-0320 affects OpenOffice.org versions 2.0.3 up to 2.3.1 and includes 2.1, 2.2, and 2.2.1.
4
What exploit type is associated with CVE-2008-0320?
CVE-2008-0320 is associated with a heap-based buffer overflow vulnerability.
5
Can CVE-2008-0320 lead to denial of service?
Yes, CVE-2008-0320 can cause a denial of service by crashing the application when a malicious OLE file is opened.