CVE-2015-5212
MEDIUM severity · CVSS 6.8 · CWE-191
6.8CVSS MEDIUM
Summary
Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via crafted PrinterSetup data in an ODF document.
Impact & exploitability
Attack vectorNetwork
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)9%
AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected products we track (2)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://www.libreoffice.org/about-us/security/advisories/cve-2015-5212/Advisory
- http://www.openoffice.org/security/cves/CVE-2015-5212.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2015-2619.htmlAdvisory
- http://www.debian.org/security/2015/dsa-3394Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlAdvisory
- http://www.securityfocus.com/bid/77486Advisory
- http://www.securitytracker.com/id/1034085Advisory
- http://www.securitytracker.com/id/1034091Advisory