imPC@ndo IT

Tracker / CVE-2007-2834

CVE-2007-2834

High 9.3

Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.

Affected products and versions

apache openoffice · … → 2.3.0
canonical ubuntu_linux
debian debian_linux
sun staroffice
sun starsuite

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References