First published: Tue Apr 28 2015(Updated: )
The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =14.10 | |
Debian | =7.0 | |
Debian | =8.0 | |
Apache OpenOffice | <=4.1.1 | |
Fedora | =21 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
LibreOffice Draw | <=4.3.6 | |
LibreOffice Draw | =4.4.0 | |
LibreOffice Draw | =4.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1774 has a high severity due to its potential to cause denial of service or arbitrary code execution.
To fix CVE-2015-1774, upgrade LibreOffice to version 4.3.7 or later, or update Apache OpenOffice to version 4.1.2 or later.
CVE-2015-1774 can allow remote attackers to execute arbitrary code or crash the application by using a crafted HWP document.
CVE-2015-1774 affects LibreOffice versions prior to 4.3.7, 4.4.x before 4.4.2, and Apache OpenOffice versions prior to 4.1.2.
If you do not use LibreOffice or Apache OpenOffice, your system is not at risk from CVE-2015-1774.