CVE-2012-1149
Publication date 21 June 2012
Last updated 24 July 2024
Ubuntu priority
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.
Status
Package | Ubuntu Release | Status |
---|---|---|
libreoffice | ||
openoffice.org | ||
Patch details
Package | Patch details |
---|---|
libreoffice |
|
openoffice.org |
References
Related Ubuntu Security Notices (USN)
- USN-1495-1
- LibreOffice vulnerabilities
- 2 July 2012
- USN-1496-1
- OpenOffice.org vulnerabilities
- 2 July 2012