Denial of Service and Code Execution Vulnerability in Apache OpenOffice Impress
CVE-2016-1513

7.8HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
5 August 2016

What is CVE-2016-1513?

A vulnerability exists in the Impress tool of Apache OpenOffice that allows remote attackers to exploit crafted MetaActions in ODP or OTP files. This can result in denial of service due to out-of-bounds memory access or may allow the execution of arbitrary code. Users are advised to update to the latest version to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.