Remote Code Execution and Denial of Service in LibreOffice and Apache OpenOffice
CVE-2015-5214

Currently unrated

Key Information:

Vendor
Canonical
Vendor
CVE Published:
10 November 2015

Summary

A vulnerability in LibreOffice prior to version 4.4.6 and 5.x before 5.0.1, as well as Apache OpenOffice prior to version 4.1.2, enables remote attackers to exploit a flaw that leads to memory corruption. This issue arises when an attacker provides a specially crafted DOC file containing an index that references a non-existent bookmark. Exploitation can result in application crashes or potentially allow the execution of arbitrary code within the context of the vulnerable application.

References

EPSS Score

10% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.