CVE-2010-2935
OpenOffice.Org: Integer truncation error by parsing specially-crafted Microsoft PowerPoint document
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an "integer truncation error."
simpress.bin en el módulo Impress en OpenOffice.org (OOo) v3.2.1 sobre Windows,
no maneja adecuadamente los valores enteros asociados a las propiedades de los elementos del diccionario, lo que permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) o posiblemente la ejecución de código de su elección a través de polígonos modificados en un documento PowerPoint que provoca un desbordamiento de búfer basado en memoria dinámica (heap).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-08-04 CVE Reserved
- 2010-08-25 CVE Published
- 2023-04-15 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-189: Numeric Errors
CAPEC
References (31)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html | 2017-09-19 | |
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html | 2017-09-19 | |
http://secunia.com/advisories/40775 | 2017-09-19 | |
http://secunia.com/advisories/41052 | 2017-09-19 | |
http://ubuntu.com/usn/usn-1056-1 | 2017-09-19 | |
http://www.debian.org/security/2010/dsa-2099 | 2017-09-19 | |
http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml | 2017-09-19 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2010:221 | 2017-09-19 | |
http://www.redhat.com/support/errata/RHSA-2010-0643.html | 2017-09-19 | |
http://www.vupen.com/english/advisories/2010/2003 | 2017-09-19 | |
http://www.vupen.com/english/advisories/2010/2149 | 2017-09-19 | |
https://bugzilla.redhat.com/show_bug.cgi?id=622529 | 2010-08-23 | |
https://access.redhat.com/security/cve/CVE-2010-2935 | 2010-08-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openoffice Search vendor "Openoffice" | Openoffice.org Search vendor "Openoffice" for product "Openoffice.org" | 3.2.1 Search vendor "Openoffice" for product "Openoffice.org" and version "3.2.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|