CVE-2014-9275: Buffer Overflow
Published Dec 9, 2014
·Updated
UnRTF allows remote attackers to cause a denial of service (out-of-bounds memory access and crash) and possibly execute arbitrary code via a crafted RTF file.
Affected Software
1 affected component
Unrtf Project Unrtf<=0.21.6
Event History
Dec 9, 2014
CVE Published
via MITRE·10:52 PM
Data Sourced
via MITRE·10:52 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9275?
CVE-2014-9275 has a severity rating that indicates it can lead to denial of service and potentially allow remote code execution.
2
How do I fix CVE-2014-9275?
To fix CVE-2014-9275, upgrade to UnRTF version 0.21.7 or later, which addresses this vulnerability.
3
What types of attacks can exploit CVE-2014-9275?
CVE-2014-9275 can be exploited by remote attackers through crafted RTF files to cause crashes or execute arbitrary code.
4
Which versions of UnRTF are affected by CVE-2014-9275?
Versions of UnRTF up to and including 0.21.6 are affected by CVE-2014-9275.
5
Is CVE-2014-9275 a local or remote vulnerability?
CVE-2014-9275 is a remote vulnerability that allows attackers to exploit the flaw without local access.