RULE(RULE ID:315986)

Rule General Information
Release Date: 2015-01-12
Rule Name: Openoffice.org XPM File Processing Integer Overflow Vulnerability (CVE-2009-2949)
Severity:
CVE ID:
Rule Protection Details
Description: Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow.
Impact: An attacker can exploit the affected software with an integer overflow vulnerability. Successful exploit leads to execute arbitrary code, and failed exploit may disturb the software logic and cause denial of service.
Affected OS: Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:38218
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://download.openoffice.org/