PT-2010-1161 · Apache+1 · Openoffice.Org+2
Jan Lieskovsky
·
Publicado
2010-08-23
·
Atualizado
2024-06-15
·
CVE-2010-2935
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenOffice.org (OOo) versions 2.x through 3.x before 3.3
Description
The issue is related to an integer truncation error in the Impress module, specifically in the simpress.bin component. This error occurs when handling integer values associated with dictionary property items, which can lead to a heap-based buffer overflow. As a result, remote attackers can potentially cause a denial of service, such as an application crash, or possibly execute arbitrary code via a crafted PowerPoint document. The vulnerability may also allow attackers to access or modify confidential data.
Recommendations
For OpenOffice.org (OOo) versions 2.x through 3.x before 3.3, update to version 3.3 or later to resolve the issue.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openoffice
Openoffice.Org
Red Hat