CVE-2009-2949
published 2010-02-16CVE-2009-2949: Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute…
PriorityP351critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
14.09%
96.2th percentile
Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | < 3.2.0 | 3.2.0 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is triggered via a crafted XPM file (or an OOo document with an embedded XPM file) opened in OpenOffice.org before 3.2; monitor for suspicious XPM file opens or OOo documents containing embedded XPM data. ↗
- →The vulnerable code path is XPMReader::ReadXPM in filter.vcl/ixpm/svt_xpmread.cxx; code-level detection or binary diffing should focus on this function for integer overflow leading to heap overflow. ↗
- →Attack vector is not limited to standalone XPM files — malicious XPM content can be embedded inside OpenOffice.org documents (.odt, .odg, etc.); inspect OOo documents for embedded XPM streams as a detection signal. ↗
- →Exploitation runs with the privileges of the user running OpenOffice.org; post-exploitation process activity should be correlated to the OOo process (soffice.bin / soffice) as the parent. ↗
- ·Affected versions are OpenOffice.org before 3.2; systems running OOo 3.2 or later are not vulnerable to this specific integer overflow. ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Sun OpenOffice up to 3.1.1 XPMReader::ReadXPM numeric error (Nessus ID 67995 / ID 165587)
vuldb·2026-04-30·CVSS 9.3
CVE-2009-2949 [CRITICAL] Sun OpenOffice up to 3.1.1 XPMReader::ReadXPM numeric error (Nessus ID 67995 / ID 165587)
A vulnerability has been found in Sun OpenOffice up to 3.1.1 and classified as critical. Impacted is the function XPMReader::ReadXPM. This manipulation causes numeric error.
The identification of this vulnerability is CVE-2009-2949. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
GHSA
GHSA-w328-4vjc-f7p4: Integer overflow in the XPMReader::ReadXPM function in filter
ghsa_unreviewed·2022-05-02
CVE-2009-2949 [HIGH] CWE-190 GHSA-w328-4vjc-f7p4: Integer overflow in the XPMReader::ReadXPM function in filter
Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow.
Ubuntu
OpenOffice.org vulnerabilities
vendor_ubuntu·2010-02-24·CVSS 5.0
CVE-2009-0217 [MEDIUM] OpenOffice.org vulnerabilities
Title: OpenOffice.org vulnerabilities
Summary: OpenOffice.org vulnerabilities
It was discovered that the XML HMAC signature system did not
correctly check certain lengths. If an attacker sent a truncated
HMAC, it could bypass authentication, leading to potential privilege
escalation. (CVE-2009-0217)
Sebastian Apelt and Frank Reißner discovered that OpenOffice did not
correctly import XPM and GIF images. If a user were tricked into opening
a specially crafted image, an attacker could execute arbitrary code with
user privileges. (CVE-2009-2949, CVE-2009-2950)
Nicolas Joly discovered that OpenOffice did not correctly handle
certain Word documents. If a user were tricked into opening a specially
crafted document, an attacker could execute arbitrary code with user
privileges. (CVE-2009-3301
Red Hat
openoffice.org: integer overflow in XPM processing
vendor_redhat·2010-02-12·CVSS 9.3
CVE-2009-2949 [CRITICAL] CWE-190 openoffice.org: integer overflow in XPM processing
openoffice.org: integer overflow in XPM processing
Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00005.htmlhttp://secunia.com/advisories/38567http://secunia.com/advisories/38568http://secunia.com/advisories/38695http://secunia.com/advisories/38921http://secunia.com/advisories/41818http://secunia.com/advisories/60799http://securitytracker.com/id?1023591http://www.debian.org/security/2010/dsa-1995http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:221http://www.openoffice.org/security/bulletin.htmlhttp://www.openoffice.org/security/cves/CVE-2009-2949.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0101.htmlhttp://www.securityfocus.com/bid/38218http://www.ubuntu.com/usn/USN-903-1http://www.us-cert.gov/cas/techalerts/TA10-287A.htmlhttp://www.vupen.com/english/advisories/2010/0366http://www.vupen.com/english/advisories/2010/0635http://www.vupen.com/english/advisories/2010/2905https://bugzilla.redhat.com/show_bug.cgi?id=527540https://exchange.xforce.ibmcloud.com/vulnerabilities/56236https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10176http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00005.htmlhttp://secunia.com/advisories/38567http://secunia.com/advisories/38568http://secunia.com/advisories/38695http://secunia.com/advisories/38921http://secunia.com/advisories/41818http://secunia.com/advisories/60799http://securitytracker.com/id?1023591http://www.debian.org/security/2010/dsa-1995http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:221http://www.openoffice.org/security/bulletin.htmlhttp://www.openoffice.org/security/cves/CVE-2009-2949.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0101.htmlhttp://www.securityfocus.com/bid/38218http://www.ubuntu.com/usn/USN-903-1http://www.us-cert.gov/cas/techalerts/TA10-287A.htmlhttp://www.vupen.com/english/advisories/2010/0366http://www.vupen.com/english/advisories/2010/0635http://www.vupen.com/english/advisories/2010/2905https://bugzilla.redhat.com/show_bug.cgi?id=527540https://exchange.xforce.ibmcloud.com/vulnerabilities/56236https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10176
2010-02-16
Published