CVE-2009-3301
published 2010-02-16CVE-2009-3301: Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or…
PriorityP345critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
12.09%
95.7th percentile
Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | < 3.2.0 | 3.2.0 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenOffice.org vulnerabilities
vendor_ubuntu·2010-02-24·CVSS 5.0
CVE-2009-0217 [MEDIUM] OpenOffice.org vulnerabilities
Title: OpenOffice.org vulnerabilities
Summary: OpenOffice.org vulnerabilities
It was discovered that the XML HMAC signature system did not
correctly check certain lengths. If an attacker sent a truncated
HMAC, it could bypass authentication, leading to potential privilege
escalation. (CVE-2009-0217)
Sebastian Apelt and Frank Reißner discovered that OpenOffice did not
correctly import XPM and GIF images. If a user were tricked into opening
a specially crafted image, an attacker could execute arbitrary code with
user privileges. (CVE-2009-2949, CVE-2009-2950)
Nicolas Joly discovered that OpenOffice did not correctly handle
certain Word documents. If a user were tricked into opening a specially
crafted document, an attacker could execute arbitrary code with user
privileges. (CVE-2009-3301
Red Hat
OpenOffice.org Word sprmTDefTable Memory Corruption
vendor_redhat·2010-02-12·CVSS 9.3
CVE-2009-3301 [CRITICAL] OpenOffice.org Word sprmTDefTable Memory Corruption
OpenOffice.org Word sprmTDefTable Memory Corruption
Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.
VulDB
Sun OpenOffice up to 3.1.1 Table Property numeric error (Nessus ID 44598 / ID 165587)
vuldb·2026-04-30·CVSS 9.3
CVE-2009-3301 [CRITICAL] Sun OpenOffice up to 3.1.1 Table Property numeric error (Nessus ID 44598 / ID 165587)
A vulnerability was found in Sun OpenOffice up to 3.1.1. It has been classified as critical. The impacted element is an unknown function of the component Table Property. Performing a manipulation results in numeric error.
This vulnerability is identified as CVE-2009-3301. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-88w6-q5j8-vrrr: Integer underflow in filter/ww8/ww8par2
ghsa_unreviewed·2022-05-02
CVE-2009-3301 [HIGH] CWE-191 GHSA-88w6-q5j8-vrrr: Integer underflow in filter/ww8/ww8par2
Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3302 OpenOffice.org Word sprmTSetBrc Memory Corruption
bugzilla·2009-11-04·CVSS 9.3
CVE-2009-3302 [CRITICAL] CVE-2009-3302 OpenOffice.org Word sprmTSetBrc Memory Corruption
CVE-2009-3302 OpenOffice.org Word sprmTSetBrc Memory Corruption
A boundary error flaw, possibly leading to a heap-based
buffer overflow, was found in the way OpenOffice.org parsed
certain records in Microsoft Word documents. An attacker could
create a specially-crafted Microsoft Word document, which once
opened by a local, unsuspecting user, could cause OpenOffice.org
to crash or, potentially, execute arbitrary code with the
permissions of the user running OpenOffice.org.
Credit: Nicolas Joly of VUPEN Vulnerability Research Team
Discussion:
This issue has been assigned CVE-2009-3302
---
Created attachment 374027
fix (combined with that of CVE-2009-3301)
---
Public now via:
http://www.openoffice.org/security/bulletin.html
---
http://www.openoffice.org/security/cves/CVE-2009-3301-3
Bugzilla
CVE-2009-3301 OpenOffice.org Word sprmTDefTable Memory Corruption
bugzilla·2009-11-04·CVSS 9.3
CVE-2009-3301 [CRITICAL] CVE-2009-3301 OpenOffice.org Word sprmTDefTable Memory Corruption
CVE-2009-3301 OpenOffice.org Word sprmTDefTable Memory Corruption
An integer underflow flaw, possibly leading to a heap-based
buffer overflow, was found in the way OpenOffice.org parsed
certain records in Microsoft Word documents. An attacker could
create a specially-crafted Microsoft Word document, which once
opened by a local, unsuspecting user, could cause OpenOffice.org
to crash or, potentially, execute arbitrary code with the
permissions of the user running OpenOffice.org.
Credit: Nicolas Joly of VUPEN Vulnerability Research Team
Discussion:
This issue has been assigned CVE-2009-3301
---
Created attachment 374028
fix (combined with that of CVE-2009-3302)
---
Public now via:
http://www.openoffice.org/security/bulletin.html
---
http://www.openoffice.org/security/cves/CVE-2009-
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00005.htmlhttp://secunia.com/advisories/38567http://secunia.com/advisories/38568http://secunia.com/advisories/38695http://secunia.com/advisories/38921http://secunia.com/advisories/41818http://secunia.com/advisories/60799http://securitytracker.com/id?1023591http://www.debian.org/security/2010/dsa-1995http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:221http://www.openoffice.org/security/bulletin.htmlhttp://www.openoffice.org/security/cves/CVE-2009-3301-3302.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0101.htmlhttp://www.securityfocus.com/bid/38218http://www.ubuntu.com/usn/USN-903-1http://www.us-cert.gov/cas/techalerts/TA10-287A.htmlhttp://www.vupen.com/english/advisories/2010/0366http://www.vupen.com/english/advisories/2010/0635http://www.vupen.com/english/advisories/2010/2905https://bugzilla.redhat.com/show_bug.cgi?id=533038https://exchange.xforce.ibmcloud.com/vulnerabilities/56240https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10423http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00005.htmlhttp://secunia.com/advisories/38567http://secunia.com/advisories/38568http://secunia.com/advisories/38695http://secunia.com/advisories/38921http://secunia.com/advisories/41818http://secunia.com/advisories/60799http://securitytracker.com/id?1023591http://www.debian.org/security/2010/dsa-1995http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:221http://www.openoffice.org/security/bulletin.htmlhttp://www.openoffice.org/security/cves/CVE-2009-3301-3302.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0101.htmlhttp://www.securityfocus.com/bid/38218http://www.ubuntu.com/usn/USN-903-1http://www.us-cert.gov/cas/techalerts/TA10-287A.htmlhttp://www.vupen.com/english/advisories/2010/0366http://www.vupen.com/english/advisories/2010/0635http://www.vupen.com/english/advisories/2010/2905https://bugzilla.redhat.com/show_bug.cgi?id=533038https://exchange.xforce.ibmcloud.com/vulnerabilities/56240https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10423
2010-02-16
Published