The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to embed arbitrary data into documents via crafted OLE objects.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2014-September/137657.html | vendor advisory mailing list third party advisory |
http://www.securityfocus.com/bid/69354 | broken link third party advisory vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/95420 | third party advisory vdb entry |
http://www.openoffice.org/security/cves/CVE-2014-3575.html | vendor advisory |
http://blog.documentfoundation.org/2014/08/28/libreoffice-4-3-1-fresh-announced/ | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2015-0377.html | third party advisory vendor advisory |
http://secunia.com/advisories/59877 | third party advisory broken link |
http://archives.neohapsis.com/archives/bugtraq/2014-08/0115.html | broken link mailing list |
https://security.gentoo.org/glsa/201603-05 | third party advisory vendor advisory |
http://secunia.com/advisories/59600 | third party advisory broken link |
http://www.securitytracker.com/id/1030754 | broken link third party advisory vdb entry |