Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2010-3453: CVE-2010-3453

The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.

CVE
#vulnerability#microsoft#dos

Security Vulnerability in OpenOffice.org related to Word document processing

  • Synopsis: A security vulnerability in OpenOffice.org, related to Word document processing, may lead to arbitrary code execution.
  • State: Resolved

1. Impact

A security vulnerability in OpenOffice.org, related to Word document processing, may allow a remote unprivileged user to execute arbitrary code on the system with the privileges of a local user running OpenOffice.org, if the local user opens a crafted Word document provided by the remote user.

2. Affected releases

  • All versions of OpenOffice.org 3 prior to version 3.3
  • All versions of OpenOffice.org 2

Note: Earlier versions of OpenOffice.org are no longer supported and will not be evaluated regarding this issue.

3. Symptoms

There are no predictable symptoms that would indicate this issue has occurred.

4. Relief/Workaround

To workaround the described issue, do not load documents from untrusted sources.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.3

6. Comments

OpenOffice.org acknowledges with thanks, Dan Rosenberg of Virtual Security Research.

Security Home -> Bulletin -> CVE-2010-3453_CVE-2010-3454

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907