REDHAT-BUG-640954: Buffer Overflow
Array index error, leading to heap based buffer overflow (two occurrences of invalid write by one byte) was found in the way OpenOffice.org performed scanning of the typography information of certain Microsoft Word Binary File Format (.DOC) files with certain user defined list styles (WW8). If a user opened a specially-crafted DOC file in OpenOffice.org suite tool (oowriter), it could lead to denial of service (oowriter executable crash), or possibly, execute arbitrary code with the privileges of the user running OpenOffice.org Writer.
References: [1] http://www.cs.brown.edu/people/drosenbe/research.html
Acknowledgements:
Red Hat would like to thank OpenOffice.org for reporting this issue. Upstream acknowledges Dan Rosenberg of Virtual Security Research as the original reporter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-640954?
The severity of REDHAT-BUG-640954 is classified as high due to a heap-based buffer overflow vulnerability.
How do I fix REDHAT-BUG-640954?
To fix REDHAT-BUG-640954, update OpenOffice to the latest version that addresses this vulnerability.
What software is affected by REDHAT-BUG-640954?
REDHAT-BUG-640954 affects OpenOffice.org Writer when processing certain Microsoft Word .DOC files.
What impact does REDHAT-BUG-640954 have on systems?
The impact of REDHAT-BUG-640954 includes the potential for remote code execution due to the buffer overflow.
When was REDHAT-BUG-640954 discovered?
REDHAT-BUG-640954 was reported in the context of vulnerabilities found in 2010.