An integer signedness error, leading to heap-based buffer out-ouf-bounds
read was found in the way OpenOffice.org processed certain Rich Text Format
(RTF) tags. If a user opened a specially-crafted RTF file in OpenOffice.org
suite tool (oowriter), it could lead to denial of service (oowriter executable
crash), or possibly, execute arbitrary code with the privileges of the user running OpenOffice.org Writer.
References:
[1] http://www.cs.brown.edu/people/drosenbe/research.html
Acknowledgements:
Red Hat would like to thank OpenOffice.org for reporting this issue. Upstream acknowledges Dan Rosenberg of Virtual Security Research as the original reporter.
Comment 12Huzaifa S. Sidhpurwala
2011-01-27 03:49:18 UTC