Vulnerability Details CVE-2012-2665
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.073
EPSS Ranking 91.2%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2012-2665
-
cpe:2.3:a:apache:openoffice:-
-
cpe:2.3:a:apache:openoffice:1.0.2
-
cpe:2.3:a:apache:openoffice:1.0.3
-
cpe:2.3:a:apache:openoffice:1.1.0
-
cpe:2.3:a:apache:openoffice:1.1.4
-
cpe:2.3:a:apache:openoffice:1.1.5
-
cpe:2.3:a:apache:openoffice:2.0.0
-
cpe:2.3:a:apache:openoffice:2.0.1
-
cpe:2.3:a:apache:openoffice:2.0.2
-
cpe:2.3:a:apache:openoffice:2.0.3
-
cpe:2.3:a:apache:openoffice:2.0.4
-
cpe:2.3:a:apache:openoffice:2.1.0
-
cpe:2.3:a:apache:openoffice:2.2.0
-
cpe:2.3:a:apache:openoffice:2.2.1
-
cpe:2.3:a:apache:openoffice:2.3.0
-
cpe:2.3:a:apache:openoffice:2.3.1
-
cpe:2.3:a:apache:openoffice:2.4.0
-
cpe:2.3:a:apache:openoffice:2.4.1
-
cpe:2.3:a:apache:openoffice:2.4.2
-
cpe:2.3:a:apache:openoffice:2.4.3
-
cpe:2.3:a:apache:openoffice:3.0.0
-
cpe:2.3:a:apache:openoffice:3.0.1
-
cpe:2.3:a:apache:openoffice:3.1.0
-
cpe:2.3:a:apache:openoffice:3.1.1
-
cpe:2.3:a:apache:openoffice:3.2.0
-
cpe:2.3:a:apache:openoffice:3.2.1
-
cpe:2.3:a:apache:openoffice:3.3.0
-
cpe:2.3:a:apache:openoffice:3.4.0
-
cpe:2.3:a:libreoffice:libreoffice:-
-
cpe:2.3:a:libreoffice:libreoffice:3.2.99.2
-
cpe:2.3:a:libreoffice:libreoffice:3.2.99.3
-
cpe:2.3:a:libreoffice:libreoffice:3.3.0.1
-
cpe:2.3:a:libreoffice:libreoffice:3.3.0.2
-
cpe:2.3:a:libreoffice:libreoffice:3.3.0.3
-
cpe:2.3:a:libreoffice:libreoffice:3.3.0.4
-
cpe:2.3:a:libreoffice:libreoffice:3.3.1.1
-
cpe:2.3:a:libreoffice:libreoffice:3.3.2.1
-
cpe:2.3:a:libreoffice:libreoffice:3.3.202
-
cpe:2.3:a:libreoffice:libreoffice:3.3.3.1
-
cpe:2.3:a:libreoffice:libreoffice:3.3.4.1
-
cpe:2.3:a:libreoffice:libreoffice:3.3.99.1
-
cpe:2.3:a:libreoffice:libreoffice:3.3.99.2
-
cpe:2.3:a:libreoffice:libreoffice:3.3.99.3
-
cpe:2.3:a:libreoffice:libreoffice:3.3.99.4
-
cpe:2.3:a:libreoffice:libreoffice:3.3.99.5
-
cpe:2.3:a:libreoffice:libreoffice:3.4.0.1
-
cpe:2.3:a:libreoffice:libreoffice:3.4.0.2
-
cpe:2.3:a:libreoffice:libreoffice:3.4.1.1
-
cpe:2.3:a:libreoffice:libreoffice:3.4.2.1
-
cpe:2.3:a:libreoffice:libreoffice:3.4.2.2
-
cpe:2.3:a:libreoffice:libreoffice:3.4.2.3
-
cpe:2.3:a:libreoffice:libreoffice:3.4.6
-
cpe:2.3:a:libreoffice:libreoffice:3.4.99.0
-
cpe:2.3:a:libreoffice:libreoffice:3.4.99.1
-
cpe:2.3:a:libreoffice:libreoffice:3.4.99.2
-
cpe:2.3:a:libreoffice:libreoffice:3.4.99.3
-
cpe:2.3:a:libreoffice:libreoffice:3.5.0
-
cpe:2.3:a:libreoffice:libreoffice:3.5.0.0
-
cpe:2.3:a:libreoffice:libreoffice:3.5.0.1
-
cpe:2.3:a:libreoffice:libreoffice:3.5.0.2
-
cpe:2.3:a:libreoffice:libreoffice:3.5.0.3
-
cpe:2.3:a:libreoffice:libreoffice:3.5.1.1
-
cpe:2.3:a:libreoffice:libreoffice:3.5.1.2
-
cpe:2.3:a:libreoffice:libreoffice:3.5.2
-
cpe:2.3:a:libreoffice:libreoffice:3.5.2.1
-
cpe:2.3:a:libreoffice:libreoffice:3.5.2.2
-
cpe:2.3:a:libreoffice:libreoffice:3.5.3.1
-
cpe:2.3:a:libreoffice:libreoffice:3.5.3.2
-
cpe:2.3:a:libreoffice:libreoffice:3.5.4.1
-
cpe:2.3:a:libreoffice:libreoffice:3.5.4.2
-
cpe:2.3:o:canonical:ubuntu_linux:10.04
-
cpe:2.3:o:canonical:ubuntu_linux:11.04
-
cpe:2.3:o:canonical:ubuntu_linux:11.10
-
cpe:2.3:o:canonical:ubuntu_linux:12.04
-
cpe:2.3:o:debian:debian_linux:6.0
-
cpe:2.3:o:debian:debian_linux:7.0
-
cpe:2.3:o:redhat:enterprise_linux:6.0
-
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0
-
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:6.0
-
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:6.0
-
cpe:2.3:o:redhat:enterprise_linux_server:6.0
-
cpe:2.3:o:redhat:enterprise_linux_server_from_rhui_6:6.0
-
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0