CVE-2009-3302: Code Injection
A boundary error flaw, possibly leading to a heap-based buffer overflow, was found in the way OpenOffice.org parsed certain records in Microsoft Word documents. An attacker could create a specially-crafted Microsoft Word document, which once opened by a local, unsuspecting user, could cause OpenOffice.org to crash or, potentially, execute arbitrary code with the permissions of the user running OpenOffice.org.
Credit: Nicolas Joly of VUPEN Vulnerability Research Team
Other sources
filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTSetBrc table property modifier in a Word document, related to a "boundary error flaw."
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3302?
CVE-2009-3302 is classified as a medium severity vulnerability due to its potential to cause application crashes and execute arbitrary code.
How do I fix CVE-2009-3302?
To fix CVE-2009-3302, update to a version of OpenOffice.org later than 3.2 or apply the appropriate security patches provided by your software vendor.
Which versions of OpenOffice.org are affected by CVE-2009-3302?
CVE-2009-3302 affects all OpenOffice.org versions prior to 3.2, including specific Red Hat and Debian releases noted in the vulnerability report.
What type of vulnerability is CVE-2009-3302?
CVE-2009-3302 is a boundary error flaw that allows denial of service and potentially arbitrary code execution through crafted Word documents.
Can CVE-2009-3302 lead to data breaches?
While CVE-2009-3302 primarily causes denial of service, the ability to execute arbitrary code could potentially lead to data breaches if exploited.