OpenOffice < 3.3 Multiple Vulnerabilities

high Nessus Network Monitor Plugin ID 5745

Synopsis

The remote host has a program that is affected by multiple vulnerabilities.

Description

Versions of OpenOffice earlier than 3.3 are potentially affected by several issues :

- Issues exist relating to PowerPoint document parsing that may lead to arbitrary code execution. (CVE-2010-2935, CVE-2010-2936)

- A directory traversal vulnerability exists in zip / jar package extraction. (CVE-2010-3450)

- Issues exist relating to RTF document processing that may lead to arbitrary code execution. (CVE-2010-3451, CVE-2010-3452)

- Issues exist relating to Word document processing that may lead to arbitrary code execution. (CVE-2010-3453, CVE-2010-3454)

- The OpenOffice.org start script and other shell scripts expand the LD_LIBRARY_PATH in a way that the current directory might be searched for libraries before /lib and /usr/lib. (CVE-2010-3689)

- Issues exist in the third party XPDF library relating to PDf processing that may allow arbitrary code execution. (CVE-2010-3702, CVE-2010-3704)

- OpenOffice.org includes a version of LIBXML2 that is affected by multiple vulnerabilities. (CVE-2010-4008, CVE-2010-4494)

- An issue exists with PNG file processing that may allow arbitrary code execution. (CVE-2010-4253)

- An issue exists with TGA file processing that may allow arbitrary code execution. (CVE-2010-4643)

Solution

Upgrade to OpenOffice version 3.3 or later.

See Also

http://archives.neohapsis.com/archives/fulldisclosure/2011-01/0490.html

http://www.openoffice.org/security/cves/CVE-2010-2935_CVE-2010-2936.html

http://www.openoffice.org/security/cves/CVE-2010-3450.html

http://www.openoffice.org/security/cves/CVE-2010-3451_CVE-2010-3452.html

http://www.openoffice.org/security/cves/CVE-2010-3453_CVE-2010-3454.html

http://www.openoffice.org/security/cves/CVE-2010-3689.html

http://www.openoffice.org/security/cves/CVE-2010-3702_CVE-2010-3704.html

http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.html

http://www.openoffice.org/security/cves/CVE-2010-4253.html

http://www.openoffice.org/security/cves/CVE-2010-4643.html

Plugin Details

Severity: High

ID: 5745

Family: Generic

Published: 1/27/2011

Updated: 3/6/2019

Nessus ID: 51773

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 7.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:sun:openoffice.org

Patch Publication Date: 1/26/2011

Vulnerability Publication Date: 1/26/2011

Reference Information

CVE: CVE-2010-2935, CVE-2010-2936, CVE-2010-3450, CVE-2010-3451, CVE-2010-3452, CVE-2010-3453, CVE-2010-3454, CVE-2010-3689, CVE-2010-3702, CVE-2010-3704, CVE-2010-4008, CVE-2010-4253, CVE-2010-4494, CVE-2010-4643

BID: 42202, 44779, 45617, 46031