CVE Vulnerabilities

CVE-2010-2935

Published: Aug 25, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an integer truncation error.

Affected Software

NameVendorStart VersionEnd Version
Openoffice.orgOpenoffice3.2.1 (including)3.2.1 (including)
Red Hat Enterprise Linux 3RedHatopenoffice.org-0:1.1.2-48.2.0.EL3*
Red Hat Enterprise Linux 4RedHatopenoffice.org-0:1.1.5-10.6.0.7.EL4.5*
Red Hat Enterprise Linux 4RedHatopenoffice.org2-1:2.0.4-5.7.0.6.1.el4_8.6*
Openoffice.orgUbuntudapper*
Openoffice.orgUbuntuhardy*
Openoffice.orgUbuntujaunty*
Openoffice.orgUbuntukarmic*
Openoffice.orgUbuntulucid*
Openoffice.orgUbuntumaverick*

References