Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-2936

Опубликовано: 26 июл. 2010
Источник: redhat
CVSS2: 6.8

Описание

Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow.

Отчет

This issue is not planned to be fixed in Red Hat Enterprise Linux 5, as its impact is mitigated by standard glibc protection mechanisms to cause only application abort. Red Hat Security Response Team does not consider a user-assisted crash (abort) of a client application, such as OpenOffice.org Impress tool, to be a security issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5openoffice.orgAffected
Red Hat Enterprise Linux 6openoffice.orgAffected
Red Hat Enterprise Linux 3openoffice.orgFixedRHSA-2010:064323.08.2010
Red Hat Enterprise Linux 4openoffice.orgFixedRHSA-2010:064323.08.2010
Red Hat Enterprise Linux 4openoffice.org2FixedRHSA-2010:064323.08.2010

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=622555OpenOffice.org: Heap-based buffer overflow by parsing specially-crafted Microsoft PowerPoint document

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 15 лет назад

Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow.

nvd
больше 15 лет назад

Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow.

debian
больше 15 лет назад

Integer overflow in simpress.bin in the Impress module in OpenOffice.o ...

github
больше 3 лет назад

Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow.

CVSS3: 9.9
fstec
больше 15 лет назад

Уязвимость модуля Impress офисного пакета OpenOffice, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

6.8 Medium

CVSS2