OpenOffice 'rtl_allocateMemory()' Heap Based Buffer Overflow Vulnerability
BID:29622
Info
OpenOffice 'rtl_allocateMemory()' Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 29622 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-2152 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2008 12:00AM |
| Updated: | Apr 13 2015 09:46PM |
| Credit: | Sean Larsson of iDefense Labs |
| Vulnerable: |
Sun StarSuite 8 Sun StarOffice 8.0 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux Optional Productivity Application 5 server RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Desktop 4.0 RedHat Desktop 3.0 Red Hat Fedora 7 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 OpenOffice OpenOffice 2.3.1 OpenOffice OpenOffice 2.3 OpenOffice OpenOffice 2.2.1 OpenOffice OpenOffice 2.2 OpenOffice OpenOffice 2.0.4 OpenOffice OpenOffice 2.0.3 -1 OpenOffice OpenOffice 2.0.3 OpenOffice OpenOffice 2.0.2 OpenOffice OpenOffice 2.0.1 OpenOffice OpenOffice 2.0 Beta OpenOffice OpenOffice 2.4 OpenOffice OpenOffice 2.2 OpenOffice OpenOffice 2.1 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Gentoo Linux |
| Not Vulnerable: |
Sun StarSuite 8 Update 11 Sun StarOffice 8.0 Update 11 OpenOffice OpenOffice 2.4.1 |
Discussion
OpenOffice 'rtl_allocateMemory()' Heap Based Buffer Overflow Vulnerability
OpenOffice is prone to a remote heap-based buffer-overflow vulnerability because of errors in processing certain files.
Remote attackers can exploit this issue by enticing victims into opening maliciously crafted OpenOffice.org document files.
Successful exploits may allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely result in a denial of service.
The issue affects OpenOffice 2 up to and including 2.4.
OpenOffice is prone to a remote heap-based buffer-overflow vulnerability because of errors in processing certain files.
Remote attackers can exploit this issue by enticing victims into opening maliciously crafted OpenOffice.org document files.
Successful exploits may allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely result in a denial of service.
The issue affects OpenOffice 2 up to and including 2.4.
Exploit / POC
OpenOffice 'rtl_allocateMemory()' Heap Based Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
OpenOffice 'rtl_allocateMemory()' Heap Based Buffer Overflow Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
OpenOffice 'rtl_allocateMemory()' Heap Based Buffer Overflow Vulnerability
References:
References:
- OpenOffice Homepage (OpenOffice)
- [ MDVSA-2008:138-1 ] - Updated OpenOffice.org packages fix vulnerability ([email protected])
- iDefense Security Advisory 06.10.08: Multiple Vendor OpenOffice rtl_allocateMemo (iDefense Labs
) - CVE-2008-2152 - Integer Overflow vulnerability in rtl_allocateMemory() (OpenOffice)
- RHSA-2008:0537-5 openoffice.org security update (Red Hat)
- RHSA-2008:0538-7 openoffice.org security update (Red Hat)
- Solution 237944: A Security Vulnerability in StarOffice/StarSuite 8 may allow fi (Sun)