CVE-2014-3693

Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:libreoffice:libreoffice:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.0.3.3:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.0.4.2:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.2.2:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.2.3:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.2.4:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.2.5:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.2.6:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.3.0:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.3.1:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:4.3.2:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*

History

13 Feb 2023, 00:42

Type Values Removed Values Added
References
  • {'url': 'http://www.libreoffice.org/about-us/security/advisories/cve-2014-3693', 'name': 'http://www.libreoffice.org/about-us/security/advisories/cve-2014-3693', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2014-3693', 'name': 'https://access.redhat.com/security/cve/CVE-2014-3693', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:0377', 'name': 'https://access.redhat.com/errata/RHSA-2015:0377', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1164733', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1164733', 'tags': [], 'refsource': 'MISC'}
Summary A use-after-free flaw was found in the "Remote Control" capabilities of the LibreOffice Impress application. An attacker could use this flaw to remotely execute code with the permissions of the user running LibreOffice Impress. Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599.

02 Feb 2023, 20:18

Type Values Removed Values Added
References
  • (MISC) http://www.libreoffice.org/about-us/security/advisories/cve-2014-3693 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2014-3693 -
  • (MISC) https://access.redhat.com/errata/RHSA-2015:0377 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1164733 -
Summary Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599. A use-after-free flaw was found in the "Remote Control" capabilities of the LibreOffice Impress application. An attacker could use this flaw to remotely execute code with the permissions of the user running LibreOffice Impress.

Information

Published : 2014-11-07 19:55

Updated : 2023-12-10 11:31


NVD link : CVE-2014-3693

Mitre link : CVE-2014-3693

CVE.ORG link : CVE-2014-3693


JSON object : View

Products Affected

redhat

  • enterprise_linux_desktop
  • enterprise_linux_workstation
  • enterprise_linux_server

opensuse

  • opensuse

libreoffice

  • libreoffice

canonical

  • ubuntu_linux