CVE-2021-25832: Buffer Overflow
Published Mar 1, 2021
·Updated
A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using this vulnerability, an attacker is able to gain remote code executions on DocumentServer.
Affected Software
1 affected component
Onlyoffice Document Server>=4.0.0-9<=6.0.0
Event History
Mar 1, 2021
CVE Published
via MITRE·03:08 PM
Data Sourced
via MITRE·03:08 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-25832?
The severity of CVE-2021-25832 is considered critical due to its potential for remote code execution.
2
How do I fix CVE-2021-25832?
To fix CVE-2021-25832, upgrade ONLYOFFICE DocumentServer to version 6.0.1 or later.
3
What systems are affected by CVE-2021-25832?
CVE-2021-25832 affects ONLYOFFICE DocumentServer versions from 4.0.0-9 to 6.0.0.
4
What type of vulnerability is CVE-2021-25832?
CVE-2021-25832 is a heap buffer overflow vulnerability found in BMP image processing.
5
Can an attacker exploit CVE-2021-25832 remotely?
Yes, an attacker can exploit CVE-2021-25832 remotely to execute arbitrary code on the affected server.