PT-2011-1225 · Apache+1 · Apache Openoffice+2

Babi

·

Published

2011-01-28

·

Updated

2023-02-13

·

CVE-2010-4643

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache OpenOffice versions 2.x through 3.x before 3.3
Description The issue is related to a heap-based buffer overflow in the Impress component of Apache OpenOffice, which can be triggered by a specially crafted Truevision TGA (TARGA) file. This can allow a remote attacker to cause a denial of service, potentially execute arbitrary code, or gain unauthorized access to sensitive data, thus compromising data integrity.
Recommendations For versions 2.x through 3.x before 3.3, update to version 3.3 or later to resolve the issue. As a temporary workaround, consider avoiding the use of TARGA files in OpenOffice until a patch is applied.

Fix

DoS

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2020-02948
CVE-2010-4643
DSA-2151-1
RHSA-2011:0181
RHSA-2011:0182
RHSA-2011:0183
RHSA-2011_0181
RHSA-2011_0182
RHSA-2011_0183

Affected Products

Apache Openoffice
Openoffice
Red Hat