CVE-2015-1774

Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 28 Apr 2015, 14:00
Last modified:06 Aug 2024, 04:54

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
6.8 MEDIUM
v2.0 (nvd)
EPSS Score
7.4% LOW
7% probability -5.25%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

28 Apr 2015, 14:00
Published
Vulnerability first disclosed
06 Aug 2024, 04:54
Last Modified
Vulnerability information updated

Description

The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.

CVSS Metrics

  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 7.40% Percentile: 92%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • apacheopenoffice

    ≤ 4.1.1

  • canonicalubuntu_linux

    12.04 | 14.04 | 14.10

  • debiandebian_linux

    7.0 | 8.0

  • fedoraprojectfedora

    21

  • libreofficelibreoffice

    ≤ 4.3.6 | 4.4.0 | 4.4.1

  • redhatenterprise_linux_desktop

    6.0

  • redhatenterprise_linux_server

    6.0

  • redhatenterprise_linux_workstation

    6.0

References (13)