Title : OpenOffice.org "rtl_allocateMemory()" Truncation Vulnerability VUPEN ID : VUPEN/ADV-2008-2449 CVE ID : CVE-2008-3282 CWE ID : CWE-197
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-28
Technical Description
A vulnerability has been identified in OpenOffice.org, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a numeric truncation error in the "rtl_allocateMemory()" [sal/rtl/source/alloc_global.c] function, which could be exploited by attackers to crash an affected application or execute arbitrary code on 64-bit platforms by tricking a user into opening a malicious file.