CVE-2022-29777: Critical severity onlyoffice document server vulnerability
Published Jun 1, 2022
·Updated
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.
Affected Software
2 affected components
Onlyoffice Core<=6.1.0.26
Onlyoffice Document Server<=6.0.0
Remediation
Event History
Jun 1, 2022
CVE Published
via MITRE·12:51 PM
Data Sourced
via MITRE·12:51 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-29777?
CVE-2022-29777 is categorized as a high severity vulnerability due to its potential to cause significant damage via heap overflow.
2
How do I fix CVE-2022-29777?
To fix CVE-2022-29777, upgrade to ONLYOFFICE Document Server version 6.1.0 or later, or Core version 6.1.0.27 or later.
3
What systems are affected by CVE-2022-29777?
CVE-2022-29777 affects ONLYOFFICE Document Server versions 6.0.0 and below, and Core versions 6.1.0.26 and below.
4
What kind of vulnerability is CVE-2022-29777?
CVE-2022-29777 is a heap overflow vulnerability that can lead to arbitrary code execution.
5
What components are impacted by CVE-2022-29777?
CVR-2022-29777 specifically impacts the font processing component in DesktopEditor via FontFileBase.h.