CVE-2014-3524: Command Injection
Published Aug 26, 2014
·Updated
Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.
Affected Software
3 affected components
Apache OpenOffice<4.1.1
LibreOffice Libreoffice<4.2.6
LibreOffice Libreoffice>=4.3.0<4.3.1
Event History
Aug 26, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3524?
CVE-2014-3524 is classified as a high-severity vulnerability that allows remote code execution.
2
How do I fix CVE-2014-3524?
To fix CVE-2014-3524, upgrade Apache OpenOffice to version 4.1.1 or later and LibreOffice to version 4.2.7 or later.
3
What types of software are affected by CVE-2014-3524?
CVE-2014-3524 affects Apache OpenOffice prior to 4.1.1 and LibreOffice versions 4.2.6 and prior as well as versions between 4.3.0 and 4.3.1.
4
What can an attacker do with CVE-2014-3524?
An attacker can execute arbitrary commands on the victim's system by exploiting a crafted Calc spreadsheet.
5
How widespread is the impact of CVE-2014-3524?
The impact of CVE-2014-3524 is significant as it can potentially allow unauthorized access and control over vulnerable systems.