Oracle OpenOffice.org < 3.3 Multiple Vulnerabilities

high Nessus Plugin ID 51773

Synopsis

The remote Windows host has a program affected by multiple vulnerabilities.

Description

The version of Oracle OpenOffice.org installed on the remote host is prior to 3.3. It is, therefore, affected by several issues :

- Issues exist relating to PowerPoint document processing that may lead to arbitrary code execution.
(CVE-2010-2935, CVE-2010-2936)

- A directory traversal vulnerability exists in zip / jar package extraction. (CVE-2010-3450)

- Issues exist relating to RTF document processing that may lead to arbitrary code execution. (CVE-2010-3451, CVE-2010-3452)

- Issues exist relating to Word document processing that may lead to arbitrary code execution. (CVE-2010-3453, CVE-2010-3454)

- Issues exist in the third-party XPDF library relating to PDF document processing that may allow arbitrary code execution. (CVE-2010-3702, CVE-2010-3704)

- OpenOffice.org includes a version of LIBXML2 that is affected by multiple vulnerabilities. (CVE-2010-4008, CVE-2010-4494)

- An issue exists with PNG file processing that may allow arbitrary code execution. (CVE-2010-4253)

- An issue exists with TGA file processing that may allow arbitrary code execution. (CVE-2010-4643)

Solution

Upgrade to Oracle OpenOffice.org version 3.3 or later.

See Also

https://seclists.org/fulldisclosure/2011/Jan/487

http://www.openoffice.org/security/cves/CVE-2010-2935_CVE-2010-2936.html

http://www.openoffice.org/security/cves/CVE-2010-3450.html

http://www.openoffice.org/security/cves/CVE-2010-3451_CVE-2010-3452.html

http://www.openoffice.org/security/cves/CVE-2010-3453_CVE-2010-3454.html

http://www.openoffice.org/security/cves/CVE-2010-3702_CVE-2010-3704.html

http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.html

http://www.openoffice.org/security/cves/CVE-2010-4253.html

http://www.openoffice.org/security/cves/CVE-2010-4643.html

Plugin Details

Severity: High

ID: 51773

File Name: openoffice_33.nasl

Version: 1.19

Type: local

Agent: windows

Family: Windows

Published: 1/27/2011

Updated: 11/15/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:oracle:openoffice.org

Required KB Items: SMB/OpenOffice/Build

Exploit Ease: No known exploits are available

Patch Publication Date: 1/26/2011

Vulnerability Publication Date: 1/26/2011

Reference Information

CVE: CVE-2010-2935, CVE-2010-2936, CVE-2010-3450, CVE-2010-3451, CVE-2010-3452, CVE-2010-3453, CVE-2010-3454, CVE-2010-3702, CVE-2010-3704, CVE-2010-4008, CVE-2010-4253, CVE-2010-4494, CVE-2010-4643

BID: 42202, 44779, 45617, 46031

Secunia: 40775