Executive Summary

Informations
NameMDVSA-2011:027First vendor Publication2011-02-14
VendorMandrivaLast vendor Modification2011-02-14
Severity (Vendor) N/ARevisionN/A

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score9.3Attack RangeNetwork
Cvss Impact Score10Attack ComplexityMedium
Cvss Expoit Score8.6AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Multiple vulnerabilities were discovered and corrected in OpenOffice.org:

Multiple directory traversal vulnerabilities allow remote attackers to overwrite arbitrary files via a .. (dot dot) in an entry in an XSLT JAR filter description file, an Extension (aka OXT) file, or unspecified other JAR or ZIP files (CVE-2010-3450).

Use-after-free vulnerability in oowriter allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via malformed tables in an RTF document (CVE-2010-3451).

Use-after-free vulnerability in oowriter allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an RTF document (CVE-2010-3452).

The WW8ListManager::WW8ListManager function in oowriter does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write (CVE-2010-3453).

Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write (CVE-2010-3454).

soffice places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory (CVE-2010-3689).

Heap-based buffer overflow in Impress allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in an ODF or Microsoft Office document, as demonstrated by a PowerPoint (aka PPT) document (CVE-2010-4253).

Heap-based buffer overflow in Impress allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TGA file in an ODF or Microsoft Office document (CVE-2010-4643).

OpenOffice.org packages have been updated in order to fix these issues. Additionally openoffice.org-voikko packages that require OpenOffice.org are also being provided and voikko package is upgraded from 2.0 to 2.2.1 version in MES5.1.

Original Source

Url : http://www.mandriva.com/security/advisories?name=MDVSA-2011:027

CWE : Common Weakness Enumeration

idName
CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer
CWE-399Resource Management Errors
CWE-264Permissions, Privileges, and Access Controls
CWE-189Numeric Errors
CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CPE : Common Platform Enumeration

TypeDescriptionCount
Application18

Open Source Vulnerability Database (OSVDB)

idDescription
70718OpenOffice.org (OOo) Impress Crafted TGA File Handling Overflow
70717OpenOffice.org (OOo) Impress Crafted PNG File Handling Overflow
70716OpenOffice.org (OOo) soffice LD_LIBRARY_PATH Zero-length Directory Name Path ...
70715OpenOffice.org (OOo) oowriter WW8DopTypography::ReadFromMem Function Crafted ...
70714OpenOffice.org (OOo) oowriter WW8ListManager::WW8ListManager Function Crafted...
70713OpenOffice.org (OOo) oowriter RTF Document Crafted Tags Use-after-free Overflow
70712OpenOffice.org (OOo) oowriter RTF Document Malformed Table Use-after-free Ove...
70711OpenOffice.org (OOo) Multiple File Type Traversal Arbitrary File Overwrite