CVE-2008-0320

Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
openofficeopenoffice.org
𝑥
≤ 2.3.1
openofficeopenoffice.org
2.0.3
openofficeopenoffice.org
2.1
openofficeopenoffice.org
2.2
openofficeopenoffice.org
2.2.1
openofficeopenoffice.org
2.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
hsqldb
hardy
not-affected
gutsy
not-affected
feisty
not-affected
dapper
not-affected
openoffice.org
hardy
not-affected
gutsy
Fixed 1:2.3.0-1ubuntu5.4
released
feisty
Fixed 2.2.0-1ubuntu6
released
dapper
Fixed 2.0.2-2ubuntu12.6
released
openoffice.org-amd64
dapper
Fixed 2.0.2-2ubuntu12.6-1
released
References