CVE-2010-3453
published 2011-01-28CVE-2010-3453: The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list…
PriorityP343critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
9.67%
95.0th percentile
The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | >= 2.0.0 < 3.3.0 | 3.3.0 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenOffice.org vulnerabilities
vendor_ubuntu·2011-02-02·CVSS 9.3
CVE-2010-2935 [CRITICAL] OpenOffice.org vulnerabilities
Title: OpenOffice.org vulnerabilities
Summary: Multiple vulnerabilities in OpenOffice.org
Charlie Miller discovered several heap overflows in PPT processing. If
a user or automated system were tricked into opening a specially crafted
PPT document, a remote attacker could execute arbitrary code with user
privileges. Ubuntu 10.10 was not affected. (CVE-2010-2935, CVE-2010-2936)
Marc Schoenefeld discovered that directory traversal was not correctly
handled in XSLT, OXT, JAR, or ZIP files. If a user or automated system
were tricked into opening a specially crafted document, a remote attacker
overwrite arbitrary files, possibly leading to arbitrary code execution
with user privileges. (CVE-2010-3450)
Dan Rosenberg discovered multiple heap overflows in RTF and DOC
processing. If a user or au
Red Hat
OpenOffice.org: Heap-based buffer overflow by processing *.doc files with WW8 list styles with specially-crafted count of list levels
vendor_redhat·2011-01-26·CVSS 9.3
CVE-2010-3453 [CRITICAL] CWE-122 OpenOffice.org: Heap-based buffer overflow by processing *.doc files with WW8 list styles with specially-crafted count of list levels
OpenOffice.org: Heap-based buffer overflow by processing *.doc files with WW8 list styles with specially-crafted count of list levels
The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.
GHSA
GHSA-wmv5-vqx6-3hcq: The WW8ListManager::WW8ListManager function in oowriter in OpenOffice
ghsa_unreviewed·2022-05-13
CVE-2010-3453 [HIGH] CWE-787 GHSA-wmv5-vqx6-3hcq: The WW8ListManager::WW8ListManager function in oowriter in OpenOffice
The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3454 OpenOffice.org: Array index error by scanning document typography information of certain *.doc files
bugzilla·2010-10-07·CVSS 9.3
CVE-2010-3454 [CRITICAL] CVE-2010-3454 OpenOffice.org: Array index error by scanning document typography information of certain *.doc files
CVE-2010-3454 OpenOffice.org: Array index error by scanning document typography information of certain *.doc files
Array index error, leading to heap based buffer overflow (two occurrences of invalid write by one byte) was found in the way OpenOffice.org performed scanning of the typography information of certain Microsoft Word Binary File Format (.DOC) files with certain user defined list styles (WW8).
If a user opened a specially-crafted DOC file in OpenOffice.org suite tool (oowriter), it could lead to denial of service (oowriter executable crash),
or possibly, execute arbitrary code with the privileges of the user running
OpenOffice.org Writer.
References:
[1] http://www.cs.brown.edu/people/drosenbe/research.html
Acknowledgements:
Red Hat would like to thank OpenOffice.org for repo
Bugzilla
CVE-2010-3453 OpenOffice.org: Heap-based buffer overflow by processing *.doc files with WW8 list styles with specially-crafted count of list levels
bugzilla·2010-10-07·CVSS 9.3
CVE-2010-3453 [CRITICAL] CVE-2010-3453 OpenOffice.org: Heap-based buffer overflow by processing *.doc files with WW8 list styles with specially-crafted count of list levels
CVE-2010-3453 OpenOffice.org: Heap-based buffer overflow by processing *.doc files with WW8 list styles with specially-crafted count of list levels
A heap-based buffer overflow was found in the way OpenOffice.org imported Microsoft Word Binary File Format (.DOC) files with certain user defined list styles (WW8). If a user opened a specially-crafted DOC file in OpenOffice.org
suite tool (oowriter), it could lead to denial of service (oowriter executable
crash), or possibly, execute arbitrary code with the privileges of the user
running OpenOffice.org Writer.
References:
[1] http://www.cs.brown.edu/people/drosenbe/research.html
Acknowledgements:
Red Hat would like to thank OpenOffice.org for reporting this issue. Upstream acknowledges Dan Rosenberg of Virtual Security Research as the or
http://osvdb.org/70714http://secunia.com/advisories/40775http://secunia.com/advisories/42999http://secunia.com/advisories/43065http://secunia.com/advisories/43105http://secunia.com/advisories/43118http://secunia.com/advisories/60799http://ubuntu.com/usn/usn-1056-1http://www.cs.brown.edu/people/drosenbe/research.htmlhttp://www.debian.org/security/2011/dsa-2151http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:027http://www.openoffice.org/security/cves/CVE-2010-3453_CVE-2010-3454.htmlhttp://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0181.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0182.htmlhttp://www.securityfocus.com/bid/46031http://www.securitytracker.com/id?1025002http://www.vsecurity.com/resources/advisory/20110126-1http://www.vupen.com/english/advisories/2011/0230http://www.vupen.com/english/advisories/2011/0232http://www.vupen.com/english/advisories/2011/0279https://bugzilla.redhat.com/show_bug.cgi?id=640950http://osvdb.org/70714http://secunia.com/advisories/40775http://secunia.com/advisories/42999http://secunia.com/advisories/43065http://secunia.com/advisories/43105http://secunia.com/advisories/43118http://secunia.com/advisories/60799http://ubuntu.com/usn/usn-1056-1http://www.cs.brown.edu/people/drosenbe/research.htmlhttp://www.debian.org/security/2011/dsa-2151http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2011:027http://www.openoffice.org/security/cves/CVE-2010-3453_CVE-2010-3454.htmlhttp://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0181.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0182.htmlhttp://www.securityfocus.com/bid/46031http://www.securitytracker.com/id?1025002http://www.vsecurity.com/resources/advisory/20110126-1http://www.vupen.com/english/advisories/2011/0230http://www.vupen.com/english/advisories/2011/0232http://www.vupen.com/english/advisories/2011/0279https://bugzilla.redhat.com/show_bug.cgi?id=640950
2011-01-28
Published