FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-0941

This CVE name corresponds to:

Entered Topic
2005-04-13 openoffice -- DOC document heap overflow vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-0941
Phase Assigned(20050331)

Description

The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.

References

Source Reference
BUGTRAQ 20050412 OpenOffice DOC document Heap Overflow
CONFIRM http://www.openoffice.org/issues/show_bug.cgi?id=46388
GENTOO GLSA-200504-13
REDHAT RHSA-2005:375
SUSE SUSE-SR:2005:021
BID 13092
OVAL oval:org.mitre.oval:def:9106
SECUNIA 17027