CVE-2012-4233: Null Pointer Dereference
LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo), allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted (1) odt file to vcllo.dll, (2) ODG (Drawing document) file to svxcorelo.dll, (3) PolyPolygon record in a .wmf (Window Meta File) file embedded in a ppt (PowerPoint) file to tllo.dll, or (4) xls (Excel) file to scfiltlo.dll.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4233?
CVE-2012-4233 has a medium severity rating due to its potential to cause denial of service.
How do I fix CVE-2012-4233?
To fix CVE-2012-4233, upgrade to LibreOffice version 3.5.7.2 or 3.6.1 or later.
What are the affected versions in CVE-2012-4233?
CVE-2012-4233 affects LibreOffice versions 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1.
What types of files are involved in CVE-2012-4233?
CVE-2012-4233 involves crafted ODT, ODG, and WMF files that can trigger the vulnerability.
Can CVE-2012-4233 be exploited remotely?
Yes, CVE-2012-4233 can be exploited remotely through specially crafted files sent to the user.