Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.812225
Kategorie:General
Titel:Apache OpenOffice Multiple DoS And Information Disclosure Vulnerabilities (Windows)
Zusammenfassung:Apache OpenOffice is prone to multiple denial of service and information disclosure vulnerabilities.
Beschreibung:Summary:
Apache OpenOffice is prone to multiple denial of service and information disclosure vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to:

- An error in the WW8Fonts Constructor in the OpenOffice Writer DOC file parser.

- An error in rendering embedded objects.

- An error in the ImportOldFormatStyles in Apache OpenOffice Writer DOC file parser.

- An error in the OpenOffice's PPT file parser in PPTStyleSheet.

Vulnerability Impact:
Successful exploitation will allow a remote
attacker to cause denial of service (memory corruption and application crash)
potentially resulting in arbitrary code execution and to retrieve sensitive
information.

Affected Software/OS:
Apache OpenOffice before 4.1.4 on Windows.

Solution:
Upgrade to Apache OpenOffice 4.1.4 or later.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: BugTraq ID: 101585
BugTraq ID: 96402
Common Vulnerability Exposure (CVE) ID: CVE-2017-9806
http://www.securityfocus.com/bid/101585
Common Vulnerability Exposure (CVE) ID: CVE-2017-3157
http://www.securityfocus.com/bid/96402
Debian Security Information: DSA-3792 (Google Search)
https://www.debian.org/security/2017/dsa-3792
RedHat Security Advisories: RHSA-2017:0914
https://access.redhat.com/errata/RHSA-2017:0914
RedHat Security Advisories: RHSA-2017:0979
https://access.redhat.com/errata/RHSA-2017:0979
http://www.securitytracker.com/id/1037893
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.