CVE-2012-2149: Apache Openoffice.org

High severity, CVSS 7.5. EPSS: 13.8% chance of exploitation in the next 30 days.

The WPXContentListener::_closeTableRow function in WPXContentListener.cpp in libwpd 0.8.8, as used by OpenOffice.org (OOo) before 3.4, allows remote attackers to execute arbitrary code via a crafted Wordperfect .WPD document that causes a negative array index to be used. NOTE: some sources report this issue as an integer overflow.

Affected products

  • Apache Openoffice.org: up to and including 3.4; version 3.3 only
  • Libwpd Libwpd: version 0.8.8 only
  • Red Hat Enterprise Linux Optional Productivity Applications: any version
  • Red Hat Enterprise Linux Desktop: version 5.0 only

Published 2012-06-21. Last modified 2026-06-16.