HTTP: LibreOffice and OpenOffice ODF Document PrinterSetup Integer Underflow

This signature detects attempts to exploit a known vulnerability in theLibreOffice and OpenOffice. A successful attack can lead to an integer underflow and arbitrary remote code execution within the context of the client.

Extended Description

Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via crafted PrinterSetup data in an ODF document.

Affected Products

Apache openoffice

References

CVE: CVE-2015-5212

Short Name
HTTP:LIBREOFFICE-INTEGR-UNDRFLW
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2015-5212 Document Integer LibreOffice ODF OpenOffice PrinterSetup Underflow and
Release Date
02/08/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3717
False Positive
Unknown
Vendors

Apache

Libreoffice

Debian

Canonical

CVSS Score

6.8

Found a potential security threat?