PT-2010-1161 · Apache+1 · Openoffice.Org+2

Jan Lieskovsky

·

Published

2010-08-23

·

Updated

2024-06-15

·

CVE-2010-2935

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenOffice.org (OOo) versions 2.x through 3.x before 3.3
Description The issue is related to an integer truncation error in the Impress module, specifically in the simpress.bin component. This error occurs when handling integer values associated with dictionary property items, which can lead to a heap-based buffer overflow. As a result, remote attackers can potentially cause a denial of service, such as an application crash, or possibly execute arbitrary code via a crafted PowerPoint document. The vulnerability may also allow attackers to access or modify confidential data.
Recommendations For OpenOffice.org (OOo) versions 2.x through 3.x before 3.3, update to version 3.3 or later to resolve the issue.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02894
CVE-2010-2935
DSA-2099-1
OPENSUSE-SU-2024:10006-1
RHSA-2010:0643
RHSA-2010_0643

Affected Products

Openoffice
Openoffice.Org
Red Hat