CVE-2008-2237: Buffer Overflow
Published Oct 30, 2008
·Updated
Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file associated with a StarOffice/StarSuite document.
Affected Software
13 affected components
OpenOffice OpenOffice.org
OpenOffice OpenOffice.org<=2.4.1
OpenOffice OpenOffice.org=2.0
OpenOffice OpenOffice.org=2.0.2
OpenOffice OpenOffice.org=2.0.3
OpenOffice OpenOffice.org=2.0.4
OpenOffice OpenOffice.org=2.1
OpenOffice OpenOffice.org=2.2
OpenOffice OpenOffice.org=2.2.1
OpenOffice OpenOffice.org=2.3
OpenOffice OpenOffice.org=2.3.1
OpenOffice OpenOffice.org=2.4
OpenOffice OpenOffice.org=2.4.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Oct 30, 2008
CVE Published
via MITRE·07:19 PM
Data Sourced
via MITRE·07:19 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2237?
CVE-2008-2237 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2008-2237?
To fix CVE-2008-2237, upgrade to Apache OpenOffice version 2.4.2 or later.
3
What type of vulnerability is CVE-2008-2237?
CVE-2008-2237 is a heap-based buffer overflow vulnerability.
4
Which versions of OpenOffice.org are affected by CVE-2008-2237?
OpenOffice.org versions 2.x before 2.4.2 are affected by CVE-2008-2237.
5
Can CVE-2008-2237 be exploited remotely?
Yes, CVE-2008-2237 can be exploited remotely through a specially crafted WMF file.