The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute arbitrary code via crafted MetaActions in an (1) ODP or (2) OTP file.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://bz.apache.org/ooo/show_bug.cgi?id=127045 | issue tracking |
http://www.securityfocus.com/bid/92079 | third party advisory vdb entry |
https://security.gentoo.org/glsa/201703-01 | vendor advisory |
http://www.securitytracker.com/id/1036443 | vdb entry |
http://www.ubuntu.com/usn/USN-3046-1 | vendor advisory |
http://www.talosintelligence.com/reports/TALOS-2016-0051/ | third party advisory |
http://www.openoffice.org/security/cves/CVE-2016-1513.html | vendor advisory |