CVE-2009-2950
published 2010-02-16CVE-2009-2950: Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows…
PriorityP343critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
13.41%
96.0th percentile
Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, related to LZW decompression.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | < 3.2.0 | 3.2.0 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenOffice.org vulnerabilities
vendor_ubuntu·2010-02-24·CVSS 5.0
CVE-2009-0217 [MEDIUM] OpenOffice.org vulnerabilities
Title: OpenOffice.org vulnerabilities
Summary: OpenOffice.org vulnerabilities
It was discovered that the XML HMAC signature system did not
correctly check certain lengths. If an attacker sent a truncated
HMAC, it could bypass authentication, leading to potential privilege
escalation. (CVE-2009-0217)
Sebastian Apelt and Frank Reißner discovered that OpenOffice did not
correctly import XPM and GIF images. If a user were tricked into opening
a specially crafted image, an attacker could execute arbitrary code with
user privileges. (CVE-2009-2949, CVE-2009-2950)
Nicolas Joly discovered that OpenOffice did not correctly handle
certain Word documents. If a user were tricked into opening a specially
crafted document, an attacker could execute arbitrary code with user
privileges. (CVE-2009-3301
Red Hat
openoffice.org: GIF file parsing heap overflow
vendor_redhat·2010-02-12·CVSS 9.3
CVE-2009-2950 [CRITICAL] openoffice.org: GIF file parsing heap overflow
openoffice.org: GIF file parsing heap overflow
Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, related to LZW decompression.
VulDB
Sun OpenOffice up to 3.1.1 GIFLZWDecompressor memory corruption (Nessus ID 44598 / ID 165587)
vuldb·2026-04-30·CVSS 9.3
CVE-2009-2950 [CRITICAL] Sun OpenOffice up to 3.1.1 GIFLZWDecompressor memory corruption (Nessus ID 44598 / ID 165587)
A vulnerability was found in Sun OpenOffice up to 3.1.1 and classified as critical. The affected element is the function GIFLZWDecompressor::GIFLZWDecompressor. Such manipulation leads to memory corruption.
This vulnerability is referenced as CVE-2009-2950. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
GHSA-jc5p-6484-2396: Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter
ghsa_unreviewed·2022-05-02
CVE-2009-2950 [HIGH] CWE-787 GHSA-jc5p-6484-2396: Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter
Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, related to LZW decompression.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-2950 openoffice.org: GIF file parsing heap overflow
bugzilla·2009-10-06·CVSS 9.3
CVE-2009-2950 [CRITICAL] CVE-2009-2950 openoffice.org: GIF file parsing heap overflow
CVE-2009-2950 openoffice.org: GIF file parsing heap overflow
It was reported that it was possible to trigger a heap overflow leading to heap memory corruption in the way that OpenOffice.org parsed GIF files. This is not restricted to GIF files alone, but to embedded GIF files in OpenOffice.org documents. The bug is found in GIFLZWDecompressor::GIFLZWDecompressor (source/filter.vcl/lgif/decode.cxx) and is triggered during LZW decompression of GIF file content.
Discussion:
This is assigned CVE-2009-2950
---
Created attachment 365023
upstream proposed patch
upstream patch, should basically be relevant for all OOo releases
---
Public now via:
http://www.openoffice.org/security/bulletin.html
---
http://www.openoffice.org/security/cves/CVE-2009-2950.html
---
This issue has been addre
Bugzilla
CVE-2009-2949 openoffice.org: integer overflow in XPM processing
bugzilla·2009-10-06·CVSS 9.3
CVE-2009-2949 [CRITICAL] CVE-2009-2949 openoffice.org: integer overflow in XPM processing
CVE-2009-2949 openoffice.org: integer overflow in XPM processing
It was reported that it was possible to trigger an integer overflow that leads to a heap overflow due to the way OpenOffice.org parsed XPM files. This could allow an attacker to execute abitrary code with the permissions of the user running OpenOffice.org, provided they could coerce them to open a malicious document containing a specially crafted XPM file. This is not restricted to XPM files alone, but to embedded XPM files in OpenOffice.org documents.
The vulnerability can be found in XPMReader::ReadXPM (source/filter.vcl/ixpm/svt_xpmread.cxx)
This vulnerability has been assigned CVE-2009-2949.
Discussion:
Created attachment 365265
same combined patch as in CVE-2009-2950
yeah, patch at CVE-2009-2950 (copied here) is th
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00005.htmlhttp://secunia.com/advisories/38567http://secunia.com/advisories/38568http://secunia.com/advisories/38695http://secunia.com/advisories/38921http://secunia.com/advisories/41818http://secunia.com/advisories/60799http://securitytracker.com/id?1023591http://www.debian.org/security/2010/dsa-1995http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:221http://www.openoffice.org/security/bulletin.htmlhttp://www.openoffice.org/security/cves/CVE-2009-2950.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0101.htmlhttp://www.securityfocus.com/bid/38218http://www.ubuntu.com/usn/USN-903-1http://www.us-cert.gov/cas/techalerts/TA10-287A.htmlhttp://www.vupen.com/english/advisories/2010/0366http://www.vupen.com/english/advisories/2010/0635http://www.vupen.com/english/advisories/2010/2905https://bugzilla.redhat.com/show_bug.cgi?id=527512https://exchange.xforce.ibmcloud.com/vulnerabilities/56238https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11050http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00005.htmlhttp://secunia.com/advisories/38567http://secunia.com/advisories/38568http://secunia.com/advisories/38695http://secunia.com/advisories/38921http://secunia.com/advisories/41818http://secunia.com/advisories/60799http://securitytracker.com/id?1023591http://www.debian.org/security/2010/dsa-1995http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:221http://www.openoffice.org/security/bulletin.htmlhttp://www.openoffice.org/security/cves/CVE-2009-2950.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0101.htmlhttp://www.securityfocus.com/bid/38218http://www.ubuntu.com/usn/USN-903-1http://www.us-cert.gov/cas/techalerts/TA10-287A.htmlhttp://www.vupen.com/english/advisories/2010/0366http://www.vupen.com/english/advisories/2010/0635http://www.vupen.com/english/advisories/2010/2905https://bugzilla.redhat.com/show_bug.cgi?id=527512https://exchange.xforce.ibmcloud.com/vulnerabilities/56238https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11050
2010-02-16
Published