CVE-2008-2238: Buffer Overflow
Published Oct 30, 2008
·Updated
Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow.
Affected Software
13 affected components
OpenOffice OpenOffice.org
OpenOffice OpenOffice.org<=2.4.1
OpenOffice OpenOffice.org=2.0
OpenOffice OpenOffice.org=2.0.2
OpenOffice OpenOffice.org=2.0.3
OpenOffice OpenOffice.org=2.0.4
OpenOffice OpenOffice.org=2.1
OpenOffice OpenOffice.org=2.2
OpenOffice OpenOffice.org=2.2.1
OpenOffice OpenOffice.org=2.3
OpenOffice OpenOffice.org=2.3.1
OpenOffice OpenOffice.org=2.4
OpenOffice OpenOffice.org=2.4.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Oct 30, 2008
CVE Published
via MITRE·07:19 PM
Data Sourced
via MITRE·07:19 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2238?
CVE-2008-2238 is classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2008-2238?
To mitigate CVE-2008-2238, it is recommended to upgrade to OpenOffice.org version 2.4.2 or later.
3
What systems are affected by CVE-2008-2238?
CVE-2008-2238 affects multiple versions of OpenOffice.org 2.x prior to 2.4.2.
4
What type of vulnerability is CVE-2008-2238?
CVE-2008-2238 is an integer overflow vulnerability that can lead to heap-based buffer overflow.
5
Can CVE-2008-2238 be exploited remotely?
Yes, CVE-2008-2238 can be exploited remotely via specially crafted EMF files.