LibreOffice < 3.3.3 / 3.4.0 LWP File Handling Overflow

high Nessus Plugin ID 55574

Synopsis

The remote Windows host has a program affected by a buffer overflow vulnerability.

Description

The version of LibreOffice installed on the remote host is earlier than 3.3.3 / 3.4.0. As such, it is reportedly affected by a stack buffer overflow in the Lotus Word Pro import filter that arises from its failure to properly handle object ids in '.lwp' documents.

If an attacker can trick a user on the affected system into importing a specially crafted .lwp document into the application, he could leverage this issue to execute arbitrary code subject to the user's privileges.

Solution

Upgrade to LibreOffice 3.3.3 / 3.4.0 or later.

See Also

http://www.nessus.org/u?49efef93

http://www.nessus.org/u?87ef8ac0

Plugin Details

Severity: High

ID: 55574

File Name: libreoffice_340.nasl

Version: 1.7

Type: local

Agent: windows

Family: Windows

Published: 7/13/2011

Updated: 7/12/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

Required KB Items: SMB/LibreOffice/Version

Exploit Ease: No known exploits are available

Patch Publication Date: 4/6/2011

Vulnerability Publication Date: 6/16/2011

Reference Information

CVE: CVE-2011-2685

BID: 48387

CERT: 953183