CVE-2012-1149
Publication date 21 June 2012
Last updated 24 July 2024
Ubuntu priority
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.
Status
Package | Ubuntu Release | Status |
---|---|---|
libreoffice | 12.04 LTS precise |
Not affected
|
11.10 oneiric |
Fixed 1:3.4.4-0ubuntu1.2
|
|
11.04 natty |
Fixed 1:3.3.4-0ubuntu1.2
|
|
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release | |
openoffice.org | 12.04 LTS precise |
Not affected
|
11.10 oneiric |
Not affected
|
|
11.04 natty |
Not affected
|
|
10.04 LTS lucid |
Fixed 1:3.2.0-7ubuntu4.3
|
|
8.04 LTS hardy | Ignored end of life |
Patch details
Package | Patch details |
---|---|
libreoffice |
|
openoffice.org |
References
Related Ubuntu Security Notices (USN)
- USN-1495-1
- LibreOffice vulnerabilities
- 2 July 2012
- USN-1496-1
- OpenOffice.org vulnerabilities
- 2 July 2012