cbcvebase.
CVE-2021-33035
published 2021-09-23

CVE-2021-33035: Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data…

PriorityP279high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
50.56%
98.8th percentile
Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack. This issue affects Apache OpenOffice up to and including version 4.1.10

Affected

8 ranges
VendorProductVersion rangeFixed in
apacheopenoffice<= 4.1.10
apache_software_foundationapache_openofficeApache OpenOffice – 4.1.10
apache_software_foundationapache_openofficeOpenOffice.org – 3.4
debianlibreoffice< libreoffice 1:4.3.1-1 (bookworm)libreoffice 1:4.3.1-1 (bookworm)
libreofficelibreoffice>= 0 < 1:4.3.1-11:4.3.1-1
libreofficelibreoffice>= 0 < 1:4.3.1-11:4.3.1-1
libreofficelibreoffice>= 0 < 1:4.3.1-11:4.3.1-1
libreofficelibreoffice>= 0 < 1:4.3.1-11:4.3.1-1

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger vector is a crafted dBase/DBF file opened in Apache OpenOffice; monitor for DBF files being opened by OpenOffice processes, especially those arriving from untrusted sources
  • The exploit results in stack-based buffer overflow leading to arbitrary code execution; look for anomalous child processes or shellcode execution spawned from the OpenOffice process after opening a DBF file
  • ·Vulnerability affects Apache OpenOffice up to and including version 4.1.10; versions patched at 4.3.1-1 (Debian packaging) are not affected
  • ·Exploitation is local-scope (requires the user to open a malicious DBF file); remote exploitation would require social engineering or a file delivery mechanism

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vulncheck7.8HIGH
vendor_debian7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.