Thursday 7 May 2009

Possible openoffice.org v3.1 function pointer manipulation /Integer overflow

I was not sure how to class this bug as i never done any research covering integer overflow's or function pointer manipulation.

The write access violation was found by replacing bytes within a specially crafted spread sheet.

I am getting in touch with a few people to see if exploitation is possible or feezable to run arbitrary code execution.

Will update in a few days.

:Update:
Information has been submitted to a company for further analysis.

No comments: