HTTP: OpenOffice.org Microsoft Word File sprmTSetBrc Processing Buffer Overflow
This signature detects attempts to exploit a known buffer overflow vulnerability in OpenOffice. It is due to an error when processing sprmTSetBrc records in Microsoft Word files. A remote unauthenticated attacker can leverage this by enticing a target user to open a malicious Microsoft Word file with a vulnerable version of the application. In a successful attack, a buffer overflow can lead to arbitrary code execution within the security context of the currently logged on user. In an unsuccessful attack, the target application can terminate abnormally.
Extended Description
OpenOffice is prone to multiple remote code-execution vulnerabilities because of errors in processing certain files. Remote attackers can exploit these issues by enticing victims into opening maliciously crafted files. Successful exploits may allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely result in a denial of service. Versions prior to OpenOffice 3.2 are vulnerable.
Affected Products
Pardus linux_2009
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Red_hat
Suse
Sun
Openoffice
Pardus
Ubuntu
Mandriva
Debian
9.3