Description
Multiple heap-based buffer overflows in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allow user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file in which values to loop counters are not properly handled in the (1) WP3TablesGroup::_readContents and (2) WP5DefinitionGroup_DefineTablesSubGroup::WP5DefinitionGroup_DefineTablesSubGroup functions. NOTE: the integer overflow has been split into CVE-2007-1466.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1268-1 | New libwpd packages fix arbitrary code execution |
Debian DSA |
DSA-1270-1 | New OpenOffice.org packages fix several vulnerabilities |
Debian DSA |
DSA-1270-2 | New OpenOffice.org packages fix several vulnerabilities |
EUVD |
EUVD-2007-0006 | Multiple heap-based buffer overflows in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allow user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file in which values to loop counters are not properly handled in the (1) WP3TablesGroup::_readContents and (2) WP5DefinitionGroup_DefineTablesSubGroup::WP5DefinitionGroup_DefineTablesSubGroup functions. NOTE: the integer overflow has been split into CVE-2007-1466. |
Ubuntu USN |
USN-437-1 | libwpd vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T12:03:36.975Z
Reserved: 2006-12-19T00:00:00.000Z
Link: CVE-2007-0002
No data.
Status : Modified
Published: 2007-03-16T21:19:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2007-0002
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN