CVE-2009-3301

HIGH
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.

References

http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00005.html

http://secunia.com/advisories/38567

http://secunia.com/advisories/38568

http://secunia.com/advisories/38695

http://secunia.com/advisories/38921

http://secunia.com/advisories/41818

http://secunia.com/advisories/60799

http://securitytracker.com/id?1023591

http://www.debian.org/security/2010/dsa-1995

http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml

http://www.mandriva.com/security/advisories?name=MDVSA-2010:221

http://www.openoffice.org/security/bulletin.html

http://www.openoffice.org/security/cves/CVE-2009-3301-3302.html

http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html

http://www.redhat.com/support/errata/RHSA-2010-0101.html

http://www.securityfocus.com/bid/38218

http://www.ubuntu.com/usn/USN-903-1

http://www.us-cert.gov/cas/techalerts/TA10-287A.html

http://www.vupen.com/english/advisories/2010/0366

http://www.vupen.com/english/advisories/2010/0635

http://www.vupen.com/english/advisories/2010/2905

https://bugzilla.redhat.com/show_bug.cgi?id=533038

https://exchange.xforce.ibmcloud.com/vulnerabilities/56240

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10423

Details

Source: MITRE

Published: 2010-02-16

Updated: 2017-09-19

Type: CWE-189

Risk Information

CVSS v2

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

Tenable Plugins

View all (22 total)

IDNameProductFamilySeverity
77467GLSA-201408-19 : OpenOffice, LibreOffice: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
67995Oracle Linux 3 / 4 : openoffice.org (ELSA-2010-0101)NessusOracle Linux Local Security Checks
high
60733Scientific Linux Security Update : openoffice.org on SL5.x i386/x86_64NessusScientific Linux Local Security Checks
high
60732Scientific Linux Security Update : openoffice.org on SL4.x i386/x86_64NessusScientific Linux Local Security Checks
high
60731Scientific Linux Security Update : openoffice.org on SL3.x i386/x86_64NessusScientific Linux Local Security Checks
high
51685SuSE 10 Security Update : OpenOffice_org (ZYPP Patch Number 6884)NessusSuSE Local Security Checks
high
51684SuSE 10 Security Update : OpenOffice_org (ZYPP Patch Number 6883)NessusSuSE Local Security Checks
high
51594SuSE 11 Security Update : OpenOffice_org (SAT Patch Number 2080)NessusSuSE Local Security Checks
high
50503Mandriva Linux Security Advisory : openoffice.org (MDVSA-2010:221)NessusMandriva Local Security Checks
high
47289Fedora 11 : openoffice.org-3.1.1-19.12.fc11 (2010-1941)NessusFedora Local Security Checks
high
47276Fedora 12 : openoffice.org-3.1.1-19.26.fc12 (2010-1847)NessusFedora Local Security Checks
high
45075openSUSE Security Update : OpenOffice_org-base-drivers-postgresql (OpenOffice_org-base-drivers-postgresql-1980)NessusSuSE Local Security Checks
high
45073openSUSE Security Update : OpenOffice_org-base-drivers-postgresql (OpenOffice_org-base-drivers-postgresql-1981)NessusSuSE Local Security Checks
high
45071openSUSE Security Update : OpenOffice_org (OpenOffice_org-1979)NessusSuSE Local Security Checks
high
45064SuSE 11 Security Update : OpenOffice_org (SAT Patch Number 2080)NessusSuSE Local Security Checks
high
44922FreeBSD : openoffice.org -- multiple vulnerabilities (c97d7a37-2233-11df-96dd-001b2134ef46)NessusFreeBSD Local Security Checks
high
44912Ubuntu 8.04 LTS / 8.10 / 9.04 / 9.10 : openoffice.org vulnerabilities (USN-903-1)NessusUbuntu Local Security Checks
high
44859Debian DSA-1995-1 : openoffice.org - several vulnerabilitiesNessusDebian Local Security Checks
high
5339OpenOffice < 3.2 Multiple VulnerabilitiesNessus Network MonitorGeneric
medium
44605RHEL 3 / 4 / 5 : openoffice.org (RHSA-2010:0101)NessusRed Hat Local Security Checks
high
44598CentOS 3 / 4 / 5 : openoffice.org (CESA-2010:0101)NessusCentOS Local Security Checks
high
44597Sun OpenOffice.org < 3.2 Multiple VulnerabilitiesNessusWindows
high