PT-2010-1160 · Apache · Openoffice

Published

2010-02-16

·

Updated

2022-02-07

·

CVE-2010-0136

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenOffice versions 2.0.4, 2.4.1, and 3.1.1
Description The issue is related to errors in applying Visual Basic for Applications (VBA) macro security settings. Exploitation of this issue may allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For version 2.0.4, consider disabling the use of VBA macros until a patch is available. For version 2.4.1, restrict the execution of VBA macros to trusted sources. For version 3.1.1, avoid opening documents from untrusted sources that may contain malicious VBA macros.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02893
CVE-2010-0136
DSA-1995-1

Affected Products

Openoffice