CVE-2007-5745 describes multiple heap-based buffer overflows in OpenOffice.org versions prior to 2.4, specifically affecting the handling of Quattro Pro (QPRO) files. This vulnerability, with a CVSS score of 6.8, allows remote attackers to cause a denial of service (crash) and potentially execute arbitrary code by crafting malicious Attribute and Font Description records within a QPRO file. While the attack complexity is medium and no public exploit code or active exploitation has been observed, its potential impact includes confidentiality, integrity, and availability compromise. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.3.1CPE matchmatch criteria | cpe:2.3:a:openoffice:openoffice:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
openoffice.org: Quattro Pro files handling heap overflows in Attribute and Font records
Apr 17, 2008Manipulated Quattro Pro files can lead to heap overflows and arbitrary code execution
Manipulated Quattro Pro files can lead to heap overflows and arbitrary code execution
Manipulated Quattro Pro files can lead to heap overflows and arbitrary code execution
Manipulated Quattro Pro files can lead to heap overflows and arbitrary code execution