Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DSA-2473-1 | openoffice.org security update |
![]() |
DSA-2487-1 | openoffice.org security update |
![]() |
EUVD-2012-1183 | Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow. |
![]() |
USN-1495-1 | LibreOffice vulnerabilities |
![]() |
USN-1496-1 | OpenOffice.org vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T18:45:27.489Z
Reserved: 2012-02-14T00:00:00
Link: CVE-2012-1149

No data.

Status : Deferred
Published: 2012-06-21T15:55:11.537
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-1149


No data.