imPC@ndo IT

Tracker / CVE-2015-1774

CVE-2015-1774

Medium 6.8

The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.

Affected products and versions

apache openoffice · … → 4.1.1
canonical ubuntu_linux
debian debian_linux
fedoraproject fedora
libreoffice libreoffice
libreoffice libreoffice · … → 4.3.6
redhat enterprise_linux_desktop
redhat enterprise_linux_server
redhat enterprise_linux_workstation

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References