CVE-2015-5212
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via crafted PrinterSetup data in an ODF document.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-5212
Vendor advisory: secalert@redhat.com — http://www.openoffice.org/security/cves/CVE-2015-5212.html
Vendor advisory: secalert@redhat.com — http://www.libreoffice.org/about-us/security/advisories/cve-2015-5212/
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 1:5.0.1~rc1-1 |
| debian | bullseye | fixed | 1:5.0.1~rc1-1 |
| debian | forky | fixed | 1:5.0.1~rc1-1 |
| debian | sid | fixed | 1:5.0.1~rc1-1 |
| debian | trixie | fixed | 1:5.0.1~rc1-1 |
| debian | 7.0 | affected | |
| debian | 8.0 | affected | |
| ubuntu | 12.04 | affected | |
| ubuntu | 14.04 | affected | |
| ubuntu | 15.04 | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| libreoffice | libreoffice | {"endIncluding":"4.4.4"} | |
| apache | openoffice | {"endIncluding":"4.1.1"} | |
References
- http://rhn.redhat.com/errata/RHSA-2015-2619.html
- http://www.debian.org/security/2015/dsa-3394
- http://www.libreoffice.org/about-us/security/advisories/cve-2015-5212/
- http://www.openoffice.org/security/cves/CVE-2015-5212.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.securityfocus.com/bid/77486
- http://www.securitytracker.com/id/1034085
- http://www.securitytracker.com/id/1034091
- http://www.ubuntu.com/usn/USN-2793-1
- https://security.gentoo.org/glsa/201603-05
- https://security.gentoo.org/glsa/201611-03
- https://security-tracker.debian.org/tracker/CVE-2015-5212
CWEs
CWE-191
Verify integrity in audit chain (admin only). AS-IS.