Múltiples vulnerabilidades en LibreOffice
|
Vulnerability classification
|
|
Property |
Value |
|
Confidence level |
Oficial |
|
Impact |
Obtener acceso |
|
Dificulty |
Experto |
|
Required attacker level |
Acceso remoto sin cuenta a un servicio exotico |
System information
|
|
Property |
Value |
|
Affected manufacturer |
GNU/Linux |
|
Affected software |
LibreOffice, versiones 3.5.4 o anteriores |
Description
|
|
Se han descubierto múltiples vulnerabilidades de desbordamiento de buffer en el código de análisis de etiquetas de ficheros XML manifest, que podrían permitir a un atacante crear un fichero especialmente diseñado en formato ODF que cuando se abriese causara ejecución de código arbitrario. |
Solution
|
|
Actualizar a la versión 3.5.5 o 3.6.0. |
Standar resources
|
|
Property |
Value |
|
CVE |
CVE-2012-2665 |
|
BID |
|
Other resources
|
CVE-2012-2665: Multiple heap-based buffer overflows in the XML manifest encryption handling code
http://www.libreoffice.org/advisories/CVE-2012-2665/ |