Back to Database
Status published
Critical
CVE-2011-2685
Stack-based buffer overflow in the Lotus Word Pro import filter...
Vulnerability Description
Stack-based buffer overflow in the Lotus Word Pro import filter in LibreOffice before 3.3.3 allows remote attackers to execute arbitrary code via a crafted .lwp file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-2685
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.opensuse.org/opensuse-updates/2011-10/msg00019.html
- http://www.openwall.com/lists/oss-security/2011/07/12/13
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:172
- http://cgit.freedesktop.org/libreoffice/filters/commit/?id=d93fa011d713100775cd3ac88c468b6830d48877
- http://www.kb.cert.org/vuls/id/953183
- http://cgit.freedesktop.org/libreoffice/filters/commit/?id=278831e37a23e9e2e29ca811c3a5398b7c67464d
- http://www.openwall.com/lists/oss-security/2011/07/06/13
More from libreoffice
View All →CVE-2018-6871
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers...
Critical
9.8
CVE-2018-14939
The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles...
Critical
9.8
CVE-2018-10583
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache...
High
7.5
CVE-2018-10119
sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses...
High
7.8
CVE-2017-8358
LibreOffice before 2017-03-17 has an out-of-bounds write caused by a...
Critical
9.8
Affected Vendor
libreoffice
View all reports →Affected Software
libreoffice
Vulnerable Versions:
0, 3.3.0, 3.3.1
Timeline
Official Publish:
July 21st, 2011
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.