PT-2010-1160 · Apache · Openoffice

Publicado

2010-02-16

·

Atualizado

2022-02-07

·

CVE-2010-0136

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenOffice versions 2.0.4, 2.4.1, and 3.1.1
Description The issue is related to errors in applying Visual Basic for Applications (VBA) macro security settings. Exploitation of this issue may allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For version 2.0.4, consider disabling the use of VBA macros until a patch is available. For version 2.4.1, restrict the execution of VBA macros to trusted sources. For version 3.1.1, avoid opening documents from untrusted sources that may contain malicious VBA macros.

Correção

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-02893
CVE-2010-0136
DSA-1995-1

Produtos afetados

Openoffice