LWN.net Logo

openoffice.org: multiple vulnerabilities

Package(s):openoffice.org CVE #(s):CVE-2010-3450 CVE-2010-3451 CVE-2010-3452 CVE-2010-3453 CVE-2010-3454 CVE-2010-3689 CVE-2010-4253 CVE-2010-4643
Created:January 26, 2011 Updated:May 9, 2011
Description: From the Debian advisory:

During an internal security audit within Red Hat, a directory traversal vulnerability has been discovered in the way OpenOffice.org 3.1.1 through 3.2.1 processes XML filter files. If a local user is tricked into opening a specially-crafted OOo XML filters package file, this problem could allow remote attackers to create or overwrite arbitrary files belonging to local user or, potentially, execute arbitrary code. (CVE-2010-3450)

During his work as a consultant at Virtual Security Research (VSR), Dan Rosenberg discovered a vulnerability in OpenOffice.org's RTF parsing functionality. Opening a maliciously crafted RTF document can caus an out-of-bounds memory read into previously allocated heap memory, which may lead to the execution of arbitrary code. (CVE-2010-3451)

Dan Rosenberg discovered a vulnerability in the RTF file parser which can be leveraged by attackers to achieve arbitrary code execution by convincing a victim to open a maliciously crafted RTF file. (CVE-2010-3452)

As part of his work with Virtual Security Research, Dan Rosenberg discovered a vulnerability in the WW8ListManager::WW8ListManager() function of OpenOffice.org that allows a maliciously crafted file to cause the execution of arbitrary code. (CVE-2010-3453)

As part of his work with Virtual Security Research, Dan Rosenberg discovered a vulnerability in the WW8DopTypography::ReadFromMem() function in OpenOffice.org that may be exploited by a maliciously crafted file which allowins an attacker to control program flow and potentially execute arbitrary code. (CVE-2010-3454)

Dmitri Gribenko discovered that the soffice script does not treat an empty LD_LIBRARY_PATH variable like an unset one, may lead to the execution of arbitrary code. (CVE-2010-3689)

A heap based buffer overflow has been discovered with unknown impact. (CVE-2010-4253)

A vulnerability has been discovered in the way OpenOffice.org handles TGA graphics which can be tricked by a specially crafted TGA file that could cause the program to crash due to a heap-based buffer overflow with unknown impact. (CVE-2010-4643)

Alerts:
SUSE SUSE-SR:2011:007 2011-04-19
openSUSE openSUSE-SU-2011:0337-1 2011-04-18
openSUSE openSUSE-SU-2011:0336-1 2011-04-18
CentOS CESA-2011:0182 2011-05-07
Fedora FEDORA-2011-0837 2011-01-27
Mandriva MDVSA-2011:027 2011-02-14
Pardus 2011-34 2011-02-12
CentOS CESA-2011:0181 2011-02-04
Ubuntu USN-1056-1 2011-02-02
Red Hat RHSA-2011:0183-01 2011-01-28
Red Hat RHSA-2011:0182-01 2011-01-28
Red Hat RHSA-2011:0181-01 2011-01-28
Debian DSA-2151-1 2011-01-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds