Summary
This host is installed with LibreOffice
and is prone to remote code execution vulnerability.
Impact
Successful exploitation will allow attackers
to cause a denial of service (crash) or possibly execute arbitrary code.
Impact Level: System/Application
Solution
Upgrade to LibreOffice 4.2.7 or 4.3.3
or later, For updates refer to http://www.libreoffice.org
Insight
Flaw exists due to use-after-free error
in the Impress Remote socket manager.
Affected
LibreOffice version 4.x prior
to 4.2.7 and 4.3.x prior to 4.3.3 on Windows
Detection
Get the installed version with the help of
detect NVT and check the version is vulnerable or not.
References
Severity
Classification
-
CVE CVE-2014-3693 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Adobe Acrobat Multiple Unspecified Vulnerabilities -01 May13 (Mac OS X)
- Adobe Acrobat Out-of-bounds Vulnerability Feb15 (Windows)
- Adobe AIR Multiple Vulnerabilities(APSB14-22)-(Mac OS X)
- Adobe Acrobat Out-of-bounds Vulnerability Feb15 (Mac OS X)
- Adobe Flash Media Server Multiple Remote Security Vulnerabilities