First published: Mon Mar 01 2021(Updated: )
A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using this vulnerability, an attacker is able to gain remote code executions on DocumentServer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ONLYOFFICE | >=4.0.0-9<=6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-25832 is considered critical due to its potential for remote code execution.
To fix CVE-2021-25832, upgrade ONLYOFFICE DocumentServer to version 6.0.1 or later.
CVE-2021-25832 affects ONLYOFFICE DocumentServer versions from 4.0.0-9 to 6.0.0.
CVE-2021-25832 is a heap buffer overflow vulnerability found in BMP image processing.
Yes, an attacker can exploit CVE-2021-25832 remotely to execute arbitrary code on the affected server.