First published: Mon Nov 19 2012(Updated: )
LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo), allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted (1) odt file to vcllo.dll, (2) ODG (Drawing document) file to svxcorelo.dll, (3) PolyPolygon record in a .wmf (Window Meta File) file embedded in a ppt (PowerPoint) file to tllo.dll, or (4) xls (Excel) file to scfiltlo.dll.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
LibreOffice Draw | <=3.6 | |
LibreOffice Draw | =3.5 | |
LibreOffice Draw | =3.5.-rc1 | |
LibreOffice Draw | =3.5.0 | |
LibreOffice Draw | =3.5.0-rc1 | |
LibreOffice Draw | =3.5.0-rc2 | |
LibreOffice Draw | =3.5.0-rc3 | |
LibreOffice Draw | =3.5.1 | |
LibreOffice Draw | =3.5.1-rc1 | |
LibreOffice Draw | =3.5.1-rc2 | |
LibreOffice Draw | =3.5.2 | |
LibreOffice Draw | =3.5.2-rc1 | |
LibreOffice Draw | =3.5.2-rc2 | |
LibreOffice Draw | =3.5.3 | |
LibreOffice Draw | =3.5.3-rc1 | |
LibreOffice Draw | =3.5.3-rc2 | |
LibreOffice Draw | =3.5.4 | |
LibreOffice Draw | =3.5.4-rc2 | |
LibreOffice Draw | =3.5.5 | |
LibreOffice Draw | =3.5.5.1 | |
LibreOffice Draw | =3.5.5.2 | |
LibreOffice Draw | =3.5.5.3 | |
LibreOffice Draw | =3.5.6 | |
LibreOffice Draw | =3.5.6.1 | |
LibreOffice Draw | =3.5.6.2 | |
LibreOffice Draw | =3.5.6.3 | |
Apache OpenOffice |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4233 has a medium severity rating due to its potential to cause denial of service.
To fix CVE-2012-4233, upgrade to LibreOffice version 3.5.7.2 or 3.6.1 or later.
CVE-2012-4233 affects LibreOffice versions 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1.
CVE-2012-4233 involves crafted ODT, ODG, and WMF files that can trigger the vulnerability.
Yes, CVE-2012-4233 can be exploited remotely through specially crafted files sent to the user.