Unrated severityNVD Advisory· Published Jun 21, 2012· Updated Apr 29, 2026
CVE-2012-1149
CVE-2012-1149
Description
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.
Affected products
14cpe:2.3:a:apache:openoffice.org:3.3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:openoffice.org:3.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:openoffice.org:3.4:beta:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:15:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:15:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:6.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_eus:6.2.z:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
23- securitytracker.com/idnvdPatchThird Party AdvisoryVDB Entry
- lists.fedoraproject.org/pipermail/package-announce/2012-June/082168.htmlnvdThird Party Advisory
- lists.fedoraproject.org/pipermail/package-announce/2012-May/081319.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2012-0705.htmlnvdThird Party Advisory
- secunia.com/advisories/49392nvdVendor Advisory
- security.gentoo.org/glsa/glsa-201209-05.xmlnvdThird Party Advisory
- www.debian.org/security/2012/dsa-2473nvdThird Party Advisory
- www.debian.org/security/2012/dsa-2487nvdThird Party Advisory
- www.gentoo.org/security/en/glsa/glsa-201408-19.xmlnvdThird Party Advisory
- www.libreoffice.org/advisories/cve-2012-1149/nvdVendor Advisory
- www.openoffice.org/security/cves/CVE-2012-1149.htmlnvdThird Party Advisory
- www.securityfocus.com/bid/53570nvdThird Party AdvisoryVDB Entry
- archives.neohapsis.com/archives/bugtraq/2012-05/0089.htmlnvdBroken Link
- www.mandriva.com/security/advisoriesnvdBroken Link
- www.mandriva.com/security/advisoriesnvdBroken Link
- www.osvdb.org/81988nvdBroken Link
- secunia.com/advisories/46992nvd
- secunia.com/advisories/47244nvd
- secunia.com/advisories/49140nvd
- secunia.com/advisories/49373nvd
- secunia.com/advisories/50692nvd
- secunia.com/advisories/60799nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/75692nvd
News mentions
0No linked articles in our index yet.