Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenOffice TIFF文件解析器输入验证错误漏洞
Vulnerability Description
Apache OpenOffice是美国阿帕奇(Apache)基金会的一款开源的办公软件套件。该套件包含文本文档、电子表格、演示文稿、绘图、数据库等。 OpenOffice处理包含畸形数据的文档时存在输入验证错误漏洞,远程攻击者可能利用此漏洞通过诱使用户打开恶意文档控制用户系统。OpenOffice组件的TIFF解析代码在解析TIFF目录项的某些标签时,解析器使用了文件中不可信任的值计算所要分配的内存数,因此如果用户提供了特定值的话就会在计算中出现整数溢出,导致分配不充分的缓冲区,而这又会触发堆溢出。成功
CVSS Information
N/A
Vulnerability Type
N/A