CVE-2012-1149: Buffer Overflow
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1149?
CVE-2012-1149 is classified as a high severity vulnerability due to its potential to cause application crashes and arbitrary code execution.
How do I fix CVE-2012-1149?
To fix CVE-2012-1149, update OpenOffice.org to version 3.4.1 or later and LibreOffice to version 3.5.3 or later.
Which versions of software are affected by CVE-2012-1149?
CVE-2012-1149 affects OpenOffice.org versions 3.3, 3.4 Beta, and earlier, as well as LibreOffice versions prior to 3.5.3.
What impact does CVE-2012-1149 have on systems?
CVE-2012-1149 can lead to a denial of service, causing application crashes, and could potentially allow remote attackers to execute arbitrary code.
Is there a patched version for CVE-2012-1149?
Yes, patched versions for CVE-2012-1149 are available in OpenOffice.org 3.4.1 and LibreOffice 3.5.3 or later.