First published: Wed Jun 01 2022(Updated: )
Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ONLYOFFICE Document Server | <=6.1.0.26 | |
ONLYOFFICE | <=6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29777 is categorized as a high severity vulnerability due to its potential to cause significant damage via heap overflow.
To fix CVE-2022-29777, upgrade to ONLYOFFICE Document Server version 6.1.0 or later, or Core version 6.1.0.27 or later.
CVE-2022-29777 affects ONLYOFFICE Document Server versions 6.0.0 and below, and Core versions 6.1.0.26 and below.
CVE-2022-29777 is a heap overflow vulnerability that can lead to arbitrary code execution.
CVR-2022-29777 specifically impacts the font processing component in DesktopEditor via FontFileBase.h.