CVE-2007-5747

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
17/04/2008
Last modified:
09/04/2025

Description

Integer underflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted values that trigger an excessive loop and a stack-based buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sun:openoffice.org:*:*:*:*:*:*:*:* 2.3.0 (including)
cpe:2.3:a:sun:openoffice.org:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:sun:openoffice.org:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:sun:openoffice.org:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:sun:openoffice.org:2.2.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools