PT-2021-4126 · Apache · Apache Openoffice+1

Eugene Lim

·

Published

2021-09-17

·

Updated

2021-12-01

·

CVE-2021-33035

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache OpenOffice versions up to and including 4.1.10
Description The issue is related to the processing of DBF files in Apache OpenOffice. When reading DBF data, the size of certain fields is not checked, and the data is copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack. This allows a remote attacker to execute arbitrary code.
Recommendations For Apache OpenOffice versions up to and including 4.1.10, update to version 4.1.11 or later, which includes the patch for this issue. As a temporary workaround, consider avoiding the use of DBF files in Apache OpenOffice until the issue is resolved. Restrict access to the DBF file handling functionality to minimize the risk of exploitation.

Fix

Buffer Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04717
CVE-2021-33035

Affected Products

Apache Openoffice
Openoffice