>> OpenOffice "SwRTFParser::ReadPrtData()" Function Command Execution Vulnerability
Title : OpenOffice "SwRTFParser::ReadPrtData()" Function Command Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-2166 CVE ID : CVE-2007-0245 - CVE-2007-2754
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-06-13
Technical Description
A vulnerability has been identified in OpenOffice.org, which could be exploited by attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a heap overflow error in the "SwRTFParser::ReadPrtData()" [filter/rtf/swparrtf.cxx] function when processing a malformed "prtdata" tag, which could be exploited by attackers to execute arbitrary code by tricking a user into opening a specially crafted RTF document.
Note : A FreeType vulnerability has also been addressed. For additional information, see : VUPEN/ADV-2007-1894