First published: Tue Nov 10 2015(Updated: )
Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a buffer overflow.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =15.04 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Apache OpenOffice | <=4.1.1 | |
The Document Foundation LibreOffice | <=4.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5213 is considered a critical vulnerability due to its potential to allow arbitrary code execution and denial of service through memory corruption.
To fix CVE-2015-5213, upgrade to LibreOffice versions 4.4.5 or later, or Apache OpenOffice versions 4.1.2 or later.
CVE-2015-5213 affects LibreOffice versions prior to 4.4.5 and Apache OpenOffice versions prior to 4.1.2.
Yes, CVE-2015-5213 can be exploited remotely by sending specially crafted DOC files to the vulnerable software.
CVE-2015-5213 affects multiple platforms including Ubuntu Linux 12.04, 14.04, 15.04, and Debian Linux versions 7.0 and 8.0.