First published: Tue Nov 10 2015(Updated: )
LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via an index to a non-existent bookmark in a DOC file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =15.04 | |
Debian | =7.0 | |
Debian | =8.0 | |
LibreOffice Draw | <=4.4.5 | |
Apache OpenOffice | <=4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5214 has been classified as a high severity vulnerability due to the potential for remote code execution and denial of service.
To fix CVE-2015-5214, update LibreOffice to version 4.4.6 or later, or Apache OpenOffice to version 4.1.2 or later.
CVE-2015-5214 can enable attackers to cause memory corruption, crash the application, or execute arbitrary code.
CVE-2015-5214 affects LibreOffice versions before 4.4.6 and 5.x before 5.0.1, and Apache OpenOffice versions before 4.1.2.
CVE-2015-5214 affects various versions of Ubuntu and Debian Linux running the vulnerable LibreOffice or Apache OpenOffice software.