INFORMATION

Name : CVE-2008-3282 First Publication : 2008-08-29
Severity : Critical Last Modification : 2008-10-03

SCORING CVSS v2

Cvss Base Score : 9.3 Attack Range : Network
Cvss Impact Score : 10 Attack Complexity : Medium
Cvss Expoit Score : 8.6 Authentification : None Required

Calculate full CVSS 2.0 Vectors scores

DETAIL

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document, related to a "numeric truncation error," a different vulnerability than CVE-2008-2152.



CWE COMMON WEAKNESS ENUMERATION

Weakness : CWE-197 - Numeric Truncation Error (From Oval)
Weakness : CWE-189 - Numeric Errors (From NVD)
CPE COMMON PLATFORM ENUMERATION (from NVD)

OPEN SOURCE VULNERABILTY DATABASE (OSVDB)

47880 : OpenOffice.org (OOo) on 64-bit alloc_global.c rtl_allocateMemory Function Crafted Document Handling Overflow.


SECONDARY(S) SOURCE(S)