CVE-2016-0794

The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*

History

12 Feb 2023, 23:16

Type Values Removed Values Added
References
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1306609', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1306609', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2016-0794', 'name': 'https://access.redhat.com/security/cve/CVE-2016-0794', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2016:2579', 'name': 'https://access.redhat.com/errata/RHSA-2016:2579', 'tags': [], 'refsource': 'MISC'}
Summary Multiple flaws were found in the Lotus Word Pro (LWP) document format parser in LibreOffice. By tricking a user into opening a specially crafted LWP document, an attacker could possibly use this flaw to execute arbitrary code with the privileges of the user opening the file. The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.

02 Feb 2023, 21:16

Type Values Removed Values Added
References
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1306609 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2016-0794 -
  • (MISC) https://access.redhat.com/errata/RHSA-2016:2579 -
Summary The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document. Multiple flaws were found in the Lotus Word Pro (LWP) document format parser in LibreOffice. By tricking a user into opening a specially crafted LWP document, an attacker could possibly use this flaw to execute arbitrary code with the privileges of the user opening the file.

Information

Published : 2016-02-18 21:59

Updated : 2023-12-10 11:46


NVD link : CVE-2016-0794

Mitre link : CVE-2016-0794

CVE.ORG link : CVE-2016-0794


JSON object : View

Products Affected

canonical

  • ubuntu_linux

libreoffice

  • libreoffice
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer