This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.

INFORMATION

Name : CVE-2008-3282 First Publication : 2008-08-29
Severity : Critical Last Modification : 2008-10-03

SCORING CVSS v2

Cvss Base Score : 9.3 Attack Range : Network
Cvss Impact Score : 10 Attack Complexity : Medium
Cvss Expoit Score : 8.6 Authentification : None Required

Calculate full CVSS 2.0 Vectors scores

DETAIL

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document, related to a "numeric truncation error," a different vulnerability than CVE-2008-2152.



CWE COMMON WEAKNESS ENUMERATION

OVALID

oval:org.mitre.oval:def:11345, Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly execute a

oval:org.mitre.oval:def:11414, The operating system installed on the system is Red Hat Enterprise Linux 5

CPE COMMON PLATFORM ENUMERATION

OPEN SOURCE VULNERABILTY DATABASE (OSVDB)

47880 : OpenOffice.org (OOo) on 64-bit alloc_global.c rtl_allocateMemory Function Crafted Document Handling Overflow.


SECONDARY(S) SOURCE(S)