cbcvebase.
CVE-2009-2949
published 2010-02-16

CVE-2009-2949: Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute…

PriorityP351critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
14.09%
96.2th percentile
Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow.

Affected

7 ranges
VendorProductVersion rangeFixed in
apacheopenoffice< 3.2.03.2.0
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered via a crafted XPM file (or an OOo document with an embedded XPM file) opened in OpenOffice.org before 3.2; monitor for suspicious XPM file opens or OOo documents containing embedded XPM data.
  • The vulnerable code path is XPMReader::ReadXPM in filter.vcl/ixpm/svt_xpmread.cxx; code-level detection or binary diffing should focus on this function for integer overflow leading to heap overflow.
  • Attack vector is not limited to standalone XPM files — malicious XPM content can be embedded inside OpenOffice.org documents (.odt, .odg, etc.); inspect OOo documents for embedded XPM streams as a detection signal.
  • Exploitation runs with the privileges of the user running OpenOffice.org; post-exploitation process activity should be correlated to the OOo process (soffice.bin / soffice) as the parent.
  • ·Affected versions are OpenOffice.org before 3.2; systems running OOo 3.2 or later are not vulnerable to this specific integer overflow.

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.