CVE-2010-3452
published 2011-01-28CVE-2010-3452: Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application…
PriorityP343critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
10.27%
95.2th percentile
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an RTF document.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | >= 2.0.0 < 3.3.0 | 3.3.0 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenOffice.org vulnerabilities
vendor_ubuntu·2011-02-02·CVSS 9.3
CVE-2010-2935 [CRITICAL] OpenOffice.org vulnerabilities
Title: OpenOffice.org vulnerabilities
Summary: Multiple vulnerabilities in OpenOffice.org
Charlie Miller discovered several heap overflows in PPT processing. If
a user or automated system were tricked into opening a specially crafted
PPT document, a remote attacker could execute arbitrary code with user
privileges. Ubuntu 10.10 was not affected. (CVE-2010-2935, CVE-2010-2936)
Marc Schoenefeld discovered that directory traversal was not correctly
handled in XSLT, OXT, JAR, or ZIP files. If a user or automated system
were tricked into opening a specially crafted document, a remote attacker
overwrite arbitrary files, possibly leading to arbitrary code execution
with user privileges. (CVE-2010-3450)
Dan Rosenberg discovered multiple heap overflows in RTF and DOC
processing. If a user or au
Red Hat
OpenOffice.org: Integer signedness error (crash) by processing certain RTF tags
vendor_redhat·2011-01-26·CVSS 9.3
CVE-2010-3452 [CRITICAL] OpenOffice.org: Integer signedness error (crash) by processing certain RTF tags
OpenOffice.org: Integer signedness error (crash) by processing certain RTF tags
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an RTF document.
GHSA
GHSA-v789-4vxg-r248: Use-after-free vulnerability in oowriter in OpenOffice
ghsa_unreviewed·2022-05-13
CVE-2010-3452 [HIGH] CWE-416 GHSA-v789-4vxg-r248: Use-after-free vulnerability in oowriter in OpenOffice
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an RTF document.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2713 openoffice.org: Out-of-bounds read in DOC sprm parser
bugzilla·2011-07-26·CVSS 9.3
CVE-2011-2713 [CRITICAL] CVE-2011-2713 openoffice.org: Out-of-bounds read in DOC sprm parser
CVE-2011-2713 openoffice.org: Out-of-bounds read in DOC sprm parser
A heap-based buffer out-ouf-bounds read was found in the way OpenOffice.org imported certain Microsoft Word Binary File Format (.DOC) file.If a user opened a specially-crafted DOC file in OpenOffice.org suite tool (oowriter), it could lead to denial of service (oowriter executable crash), or possibly, execute arbitrary code with the privileges of the user running OpenOffice.org Writer.
This has been assigned CVE-2011-2713.
Discussion:
Created attachment 515212
patch1
---
Created attachment 515213
patch2
---
Created attachment 515214
patch3
---
Created attachment 515215
patch4
---
Created attachment 515216
patch5
---
Created attachment 523579
combined backport to OpenOffice.org 3.2.1
---
This is public via:
Bugzilla
CVE-2010-3451 OpenOffice.org: Array index error by insecure parsing of broken rtf tables
bugzilla·2010-10-08·CVSS 9.3
CVE-2010-3451 [CRITICAL] CVE-2010-3451 OpenOffice.org: Array index error by insecure parsing of broken rtf tables
CVE-2010-3451 OpenOffice.org: Array index error by insecure parsing of broken rtf tables
An array index error, leading to heap based buffer overflow, was found in the way OpenOffice.org parsed RTF files.
If a user opened a specially-crafted RTF file, with broken RTF tables, in OpenOffice.org suite tool (oowriter), it could lead to denial of service (oowriter executable crash), or, possibly, execute arbitrary code with the
privileges of the user running OpenOffice.org Writer.
References:
[1] http://www.cs.brown.edu/people/drosenbe/research.html
Acknowledgements:
Red Hat would like to thank OpenOffice.org for reporting this issue. Upstream acknowledges Dan Rosenberg of Virtual Security Research as the original reporter.
Discussion:
Public via:
http://www.openoffice.org/security/cves/C
Bugzilla
CVE-2010-3452 OpenOffice.org: Integer signedness error (crash) by processing certain RTF tags
bugzilla·2010-10-05·CVSS 9.3
CVE-2010-3452 [CRITICAL] CVE-2010-3452 OpenOffice.org: Integer signedness error (crash) by processing certain RTF tags
CVE-2010-3452 OpenOffice.org: Integer signedness error (crash) by processing certain RTF tags
An integer signedness error, leading to heap-based buffer out-ouf-bounds
read was found in the way OpenOffice.org processed certain Rich Text Format
(RTF) tags. If a user opened a specially-crafted RTF file in OpenOffice.org
suite tool (oowriter), it could lead to denial of service (oowriter executable
crash), or possibly, execute arbitrary code with the privileges of the user running OpenOffice.org Writer.
References:
[1] http://www.cs.brown.edu/people/drosenbe/research.html
Acknowledgements:
Red Hat would like to thank OpenOffice.org for reporting this issue. Upstream acknowledges Dan Rosenberg of Virtual Security Research as the original reporter.
Discussion:
Public via:
http://www.openo
http://osvdb.org/70713http://secunia.com/advisories/40775http://secunia.com/advisories/42999http://secunia.com/advisories/43065http://secunia.com/advisories/43105http://secunia.com/advisories/43118http://secunia.com/advisories/60799http://ubuntu.com/usn/usn-1056-1http://www.cs.brown.edu/people/drosenbe/research.htmlhttp://www.debian.org/security/2011/dsa-2151http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:027http://www.openoffice.org/security/cves/CVE-2010-3451_CVE-2010-3452.htmlhttp://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0181.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0182.htmlhttp://www.securityfocus.com/bid/46031http://www.securitytracker.com/id?1025002http://www.vsecurity.com/resources/advisory/20110126-1http://www.vupen.com/english/advisories/2011/0230http://www.vupen.com/english/advisories/2011/0232http://www.vupen.com/english/advisories/2011/0279https://bugzilla.redhat.com/show_bug.cgi?id=640241https://exchange.xforce.ibmcloud.com/vulnerabilities/65031http://osvdb.org/70713http://secunia.com/advisories/40775http://secunia.com/advisories/42999http://secunia.com/advisories/43065http://secunia.com/advisories/43105http://secunia.com/advisories/43118http://secunia.com/advisories/60799http://ubuntu.com/usn/usn-1056-1http://www.cs.brown.edu/people/drosenbe/research.htmlhttp://www.debian.org/security/2011/dsa-2151http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:027http://www.openoffice.org/security/cves/CVE-2010-3451_CVE-2010-3452.htmlhttp://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0181.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0182.htmlhttp://www.securityfocus.com/bid/46031http://www.securitytracker.com/id?1025002http://www.vsecurity.com/resources/advisory/20110126-1http://www.vupen.com/english/advisories/2011/0230http://www.vupen.com/english/advisories/2011/0232http://www.vupen.com/english/advisories/2011/0279https://bugzilla.redhat.com/show_bug.cgi?id=640241https://exchange.xforce.ibmcloud.com/vulnerabilities/65031
2011-01-28
Published