Vulnerability Details CVE-2012-1149
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.027
EPSS Ranking 85.1%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2012-1149
-
cpe:2.3:a:apache:openoffice.org:3.3.0
-
cpe:2.3:a:apache:openoffice.org:3.4
-
cpe:2.3:a:libreoffice:libreoffice:-
-
cpe:2.3:a:libreoffice:libreoffice:3.2.99.2
-
cpe:2.3:a:libreoffice:libreoffice:3.2.99.3
-
cpe:2.3:a:libreoffice:libreoffice:3.3.0.1
-
cpe:2.3:a:libreoffice:libreoffice:3.3.0.2
-
cpe:2.3:a:libreoffice:libreoffice:3.3.0.3
-
cpe:2.3:a:libreoffice:libreoffice:3.3.0.4
-
cpe:2.3:a:libreoffice:libreoffice:3.3.1.1
-
cpe:2.3:a:libreoffice:libreoffice:3.3.2.1
-
cpe:2.3:a:libreoffice:libreoffice:3.3.202
-
cpe:2.3:a:libreoffice:libreoffice:3.3.3.1
-
cpe:2.3:a:libreoffice:libreoffice:3.3.4.1
-
cpe:2.3:a:libreoffice:libreoffice:3.3.99.1
-
cpe:2.3:a:libreoffice:libreoffice:3.3.99.2
-
cpe:2.3:a:libreoffice:libreoffice:3.3.99.3
-
cpe:2.3:a:libreoffice:libreoffice:3.3.99.4
-
cpe:2.3:a:libreoffice:libreoffice:3.3.99.5
-
cpe:2.3:a:libreoffice:libreoffice:3.4.0.1
-
cpe:2.3:a:libreoffice:libreoffice:3.4.0.2
-
cpe:2.3:a:libreoffice:libreoffice:3.4.1.1
-
cpe:2.3:a:libreoffice:libreoffice:3.4.2.1
-
cpe:2.3:a:libreoffice:libreoffice:3.4.2.2
-
cpe:2.3:a:libreoffice:libreoffice:3.4.2.3
-
cpe:2.3:a:libreoffice:libreoffice:3.4.6
-
cpe:2.3:a:libreoffice:libreoffice:3.4.99.0
-
cpe:2.3:a:libreoffice:libreoffice:3.4.99.1
-
cpe:2.3:a:libreoffice:libreoffice:3.4.99.2
-
cpe:2.3:a:libreoffice:libreoffice:3.4.99.3
-
cpe:2.3:a:libreoffice:libreoffice:3.5.0
-
cpe:2.3:a:libreoffice:libreoffice:3.5.0.0
-
cpe:2.3:a:libreoffice:libreoffice:3.5.0.1
-
cpe:2.3:a:libreoffice:libreoffice:3.5.0.2
-
cpe:2.3:a:libreoffice:libreoffice:3.5.0.3
-
cpe:2.3:a:libreoffice:libreoffice:3.5.1.1
-
cpe:2.3:a:libreoffice:libreoffice:3.5.1.2
-
cpe:2.3:a:libreoffice:libreoffice:3.5.2
-
cpe:2.3:o:debian:debian_linux:6.0
-
cpe:2.3:o:debian:debian_linux:7.0
-
cpe:2.3:o:fedoraproject:fedora:15
-
cpe:2.3:o:fedoraproject:fedora:16
-
cpe:2.3:o:redhat:enterprise_linux:5.0
-
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0
-
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0
-
cpe:2.3:o:redhat:enterprise_linux_server:6.0
-
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.2
-
cpe:2.3:o:redhat:enterprise_linux_server_eus:6.2.z
-
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0