Vulnerabilities > CVE-2009-0259 - Resource Management Errors vulnerability in Openoffice Openoffice.Org

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
openoffice
CWE-399
critical
exploit available

Summary

The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by 2008-crash.doc.rar, and a similar issue to CVE-2008-4841.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionMS Windows Wordpad .doc File Local Denial of Service PoC. CVE-2008-4841,CVE-2009-0259. Dos exploit for windows platform
fileexploits/windows/dos/6560.txt
idEDB-ID:6560
last seen2016-02-01
modified2008-09-25
platformwindows
port
published2008-09-25
reportersecurfrog
sourcehttps://www.exploit-db.com/download/6560/
titleMicrosoft Windows Wordpad - .doc File Local Denial of Service PoC
typedos

Statements

contributorTomas Hoger
lastmodified2009-01-23
organizationRed Hat
statementThis issue can only result in an OpenOffice.org crash, not allowing arbitrary code execution. Red Hat does not consider a crash of a client application such as OpenOffice.org to be a security issue.