what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

OpenOffice.org 3.3.0 Powerpoint Denial Of Service

OpenOffice.org 3.3.0 Powerpoint Denial Of Service
Posted May 17, 2012
Authored by Sven Jacobias

A review of the code in filter/source/msfilter msdffimp.cxx in OpenOffice.org versions 3.3 and 3.4 Beta revealed some unchecked memory allocations, which could be exploited via malformed Powerpoint graphics records ("escher") to cause bad_alloc exceptions. From this vulnerability a denial of service attack is possible.

tags | advisory, denial of service
advisories | CVE-2012-2334
SHA-256 | 37ba90753876b3352a8f998736c035b6682c16dcc663dc0b8448e6d9efb6e4d3

OpenOffice.org 3.3.0 Powerpoint Denial Of Service

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

CVE-2012-2334 Vulnerabilities related to malformed Powerpoint files
in OpenOffice.org 3.3.0

Reference: http://www.openoffice.org/security/cves/CVE-2012-2334.html

Severity: Important

Vendor: The Apache Software Foundation

Versions Affected:

OpenOffice.org 3.3 and 3.4 Beta, on all platforms.
Earlier versions may be also affected.

Description:

A review of the code in filter/source/msfilter msdffimp.cxx revealed
some unchecked memory allocations, which could be exploited via
malformed Powerpoint graphics records ("escher") to cause bad_alloc
exceptions. From this vulnerability a denial of service attack is
possible.

Mitigation

OpenOffice.org 3.3.0 and 3.4 beta users are advised to upgrade to
Apache OpenOffice 3.4. Users who are unable to upgrade immediately
should be cautious when opening untrusted documents.

Credits

The Apache OpenOffice Security Team credits Sven Jacobias as the
discoverer of this flaw.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAEBCgAGBQJPs8AjAAoJEGFAoYdHzLzHPiIP/15rlvzCaozoZfXAL1/0BXBA
X/gPJPqIsS88bG7CTOxmQ2fzLXj0MrCe4OIQ/piKkzglymybKcJzaOK2Kv3eCwZ1
KQeC2FDu16LBtymySuZaA86iMY4nsfWRdNkrrMYS1/pdvX6ouxEEi4zHqAKTNuhu
CusnujucvQAxXgdCEYTp7hU1ZtUPJm/4jQ2DkIqGTqusqE85IwwXNP/cw/eQbtmH
rTTw/piY69KViJbz+iSBZ8EpfFmvEbdtrz0lxwvQNGDy4em+CwjqTH5tqV4b31Ln
d5LagTQM5qdTlEAK01KDc3iPst7NrUrU5kN3ohjvpzlTGP74LqB0sTnBljm7TTCd
V7RQTxsPF8GiVeutAq/TozvL83xdqmbVKyYfZR0YYmG+6RKNMERoCkgZAKhKVaJ2
xhAOiywrU2c8QAkO4iQlP+jkGyDBf2tzjdOl7haga+upnXfTy7TfTcpxd/UTs1lx
atSPkQFpsvOexQ4yYKN687bUvmpWZzjwOEu4TmSFeOYD9KV5UGrVwt4ymkuLYl32
Brdp+1PY3fp9BWIRCy7FjY62BvW4EwbExiLr7OsKl7OmB2XWMvnS3p0owNuRrb87
i+536fO20e0cmp8BiFM6GhwY+eIJvnO77csDgEd5v+1tJGvskTFb7qss7yx/367Q
fKJPdxJyUiuOWdg9bMV0
=9Scx
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

February 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    11 Files
  • 2
    Feb 2nd
    9 Files
  • 3
    Feb 3rd
    0 Files
  • 4
    Feb 4th
    0 Files
  • 5
    Feb 5th
    0 Files
  • 6
    Feb 6th
    0 Files
  • 7
    Feb 7th
    0 Files
  • 8
    Feb 8th
    0 Files
  • 9
    Feb 9th
    0 Files
  • 10
    Feb 10th
    0 Files
  • 11
    Feb 11th
    0 Files
  • 12
    Feb 12th
    0 Files
  • 13
    Feb 13th
    0 Files
  • 14
    Feb 14th
    0 Files
  • 15
    Feb 15th
    0 Files
  • 16
    Feb 16th
    0 Files
  • 17
    Feb 17th
    0 Files
  • 18
    Feb 18th
    0 Files
  • 19
    Feb 19th
    0 Files
  • 20
    Feb 20th
    0 Files
  • 21
    Feb 21st
    0 Files
  • 22
    Feb 22nd
    0 Files
  • 23
    Feb 23rd
    0 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By
Rokasec
close