CVE-2021-33035
published 2021-09-23CVE-2021-33035: Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data…
PriorityP279high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
50.56%
98.8th percentile
Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack. This issue affects Apache OpenOffice up to and including version 4.1.10
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | openoffice | <= 4.1.10 | — |
| apache_software_foundation | apache_openoffice | Apache OpenOffice – 4.1.10 | — |
| apache_software_foundation | apache_openoffice | OpenOffice.org – 3.4 | — |
| debian | libreoffice | < libreoffice 1:4.3.1-1 (bookworm) | libreoffice 1:4.3.1-1 (bookworm) |
| libreoffice | libreoffice | >= 0 < 1:4.3.1-1 | 1:4.3.1-1 |
| libreoffice | libreoffice | >= 0 < 1:4.3.1-1 | 1:4.3.1-1 |
| libreoffice | libreoffice | >= 0 < 1:4.3.1-1 | 1:4.3.1-1 |
| libreoffice | libreoffice | >= 0 < 1:4.3.1-1 | 1:4.3.1-1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger vector is a crafted dBase/DBF file opened in Apache OpenOffice; monitor for DBF files being opened by OpenOffice processes, especially those arriving from untrusted sources ↗
- →The exploit results in stack-based buffer overflow leading to arbitrary code execution; look for anomalous child processes or shellcode execution spawned from the OpenOffice process after opening a DBF file ↗
- ·Vulnerability affects Apache OpenOffice up to and including version 4.1.10; versions patched at 4.3.1-1 (Debian packaging) are not affected ↗
- ·Exploitation is local-scope (requires the user to open a malicious DBF file); remote exploitation would require social engineering or a file delivery mechanism ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vulncheck7.8HIGH
vendor_debian7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p57v-vh5w-35p2: Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets
ghsa_unreviewed·2022-05-24
CVE-2021-33035 [HIGH] CWE-120 GHSA-p57v-vh5w-35p2: Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets
Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack. This issue affects Apache OpenOffice up to and including version 4.1.10
OSV
CVE-2021-33035: Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets
osv·2021-09-23·CVSS 7.8
CVE-2021-33035 [HIGH] CVE-2021-33035: Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets
Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack. This issue affects Apache OpenOffice up to and including version 4.1.10
VulnCheck
Apache openoffice Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
vulncheck·2021·CVSS 7.8
CVE-2021-33035 [HIGH] Apache openoffice Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Apache openoffice Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack. This issue affects Apache OpenOffice up to and including version 4.1.10
Affected: Apache openoffice
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://unit42.paloalt
Debian
CVE-2021-33035: libreoffice - Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadshee...
vendor_debian·2021·CVSS 7.8
CVE-2021-33035 [HIGH] CVE-2021-33035: libreoffice - Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadshee...
Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack. This issue affects Apache OpenOffice up to and including version 4.1.10
Scope: local
bookworm: resolved (fixed in 1:4.3.1-1)
bullseye: resolved (fixed in 1:4.3.1-1)
forky: resolved (fixed in 1:4.3.1-1)
sid: resolved (fixed in 1:4.3.1-1)
trixie: resolved (fixed in 1:4.3.1-1)
No detection rules found.
No public exploits indexed.
Unit42
Network Security Trends: November 2022-January 2023
blogs_unit42·2023-05-02·CVSS 9.8
CVE-2021-22005 [CRITICAL] Network Security Trends: November 2022-January 2023
Threat Research Center
Trend Reports
Vulnerabilities
## Network Security Trends: November 2022-January 2023
Yiheng An
Published: May 2, 2023
Trend Reports
Vulnerabilities
Attack analysis
CVE-2021-22005
CVE-2021-31602
CVE-2021-33035
CVE-2021-43287
CVE-2022-1118
CVE-2022-27924
CVE-2022-30136
CVE-2022-31137
CVE-2022-44877
CVE-2022-46169
Exploit in the wild
Network security trends
## Executive Summary
Recent observations of exploits used in the wild November 2022-January 2023 reveal that attackers have been using newly published remote code execution vulnerabilities in the following three products:
Roxy-WI, a web interface for managing and monitoring RoxyDNS
CWP, a free web hosting control panel (aka Control Web Panel or CentOS Web Panel)
Cacti, an open-source netw
Unit42
Network Security Trends: November 2022-January 2023
blogs_unit42·2023-05-02
Network Security Trends: November 2022-January 2023
## Executive Summary
Recent observations of exploits used in the wild November 2022-January 2023 reveal that attackers have been using newly published remote code execution vulnerabilities in the following three products:
- Roxy-WI, a web interface for managing and monitoring RoxyDNS
- CWP, a free web hosting control panel (aka Control Web Panel or CentOS Web Panel)
- Cacti, an open-source network monitoring and graphing tool used to track the performance of various network devices, servers and applications
Additionally, attackers have also been taking advantage of a traversal and information disclosure vulnerability in ThoughtWorks GoCD to read sensitive files stored on servers.
In our observations of network security trends, Unit 42 researchers have pinpointed several attacks based o
http://www.openwall.com/lists/oss-security/2021/10/07/3https://github.com/apache/openoffice/commit/efddaef0151af3be16078cc4d88c6bae0f911e56#diff-ea66e734dd358922aba12ad4ba39c96bdc6cbde587d07dbc63d04daa0a30e90fhttps://lists.apache.org/thread.html/r1ab8532e11f41bc7ca057ac7e39cab25f2e1f9d5f4929788ae21c8b9%40%3Cusers.openoffice.apache.org%3Ehttps://lists.apache.org/thread.html/r929c0c6a53cad64a1007b878342756badbb05ddd9b8f31a6d0b424cb%40%3Cannounce.apache.org%3Ehttp://www.openwall.com/lists/oss-security/2021/10/07/3https://github.com/apache/openoffice/commit/efddaef0151af3be16078cc4d88c6bae0f911e56#diff-ea66e734dd358922aba12ad4ba39c96bdc6cbde587d07dbc63d04daa0a30e90fhttps://lists.apache.org/thread.html/r1ab8532e11f41bc7ca057ac7e39cab25f2e1f9d5f4929788ae21c8b9%40%3Cusers.openoffice.apache.org%3Ehttps://lists.apache.org/thread.html/r929c0c6a53cad64a1007b878342756badbb05ddd9b8f31a6d0b424cb%40%3Cannounce.apache.org%3E
2021-09-23
Published
Exploited in the wild