CVE-2015-5213
Advisory lineage Upstream: 0 Downstream: 9
Modified
Published: 10 Nov 2015, 16:00
Last modified:06 Aug 2024, 06:41
Vulnerability Summary
Overall Risk (default)
medium
31/100 CVSS Score
6.8 MEDIUM
v2.0 (nvd)
EPSS Score
18.02% MEDIUM
18% probability -4.75%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
10 Nov 2015, 16:00
Published
Vulnerability first disclosed
06 Aug 2024, 06:41
Last Modified
Vulnerability information updated
Description
Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a buffer overflow.
CVSS Metrics
- v2.0•MEDIUM•Score: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 18.02%• Percentile: 95%
Techniques & Countermeasures
- CWE-189•Numeric Errors
Weaknesses in this category are related to improper calculation or conversion of numbers.
Affected Systems
- apache•openoffice
≤ 4.1.1
- canonical•ubuntu_linux
12.04 | 14.04 | 15.04
- debian•debian_linux
7.0 | 8.0
- libreoffice•libreoffice
≤ 4.4.4
References (11)
- http://www.securitytracker.com/id/1034085
- https://security.gentoo.org/glsa/201611-03
- http://www.securitytracker.com/id/1034091
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://rhn.redhat.com/errata/RHSA-2015-2619.html
- http://www.ubuntu.com/usn/USN-2793-1
- http://www.securityfocus.com/bid/77486
- http://www.openoffice.org/security/cves/CVE-2015-5213.html
- http://www.libreoffice.org/about-us/security/advisories/cve-2015-5213/
- https://security.gentoo.org/glsa/201603-05
- http://www.debian.org/security/2015/dsa-3394