CVE-2010-2936: Buffer Overflow
A short integer overflow, leading to heap-based buffer overflow was found in the way OpenOffice.org Impress presentation aplication processed polygons in input document. An attacker could use this flaw to create a specially-crafted Microsoft PowerPoint (PPT) file that, when opened, would cause simpress.bin executable to crash, or, possibly execute arbitrary code with the privileges of the user running the ooimpress tool.
References: [1] http://secunia.com/advisories/40775/ [2] http://securityevaluators.com/files/papers/CrashAnalysis.pdf [3] http://www.openoffice.org/servlets/ReadMsg?list=dev&msgNo=27690
CVE Request: [4] http://www.openwall.com/lists/oss-security/2010/08/11/1
Other sources
Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2936?
CVE-2010-2936 has a high severity rating due to its risk of allowing remote code execution through crafted files.
How do I fix CVE-2010-2936?
To fix CVE-2010-2936, update OpenOffice.org to version 3.2.1 or install the specified remedial version 1:2.0.4-5.7.0.6.1.el4_8.6.
Which software is affected by CVE-2010-2936?
CVE-2010-2936 affects OpenOffice.org versions prior to 3.2.1 and certain older versions of the redhat package openoffice.org2.
Can CVE-2010-2936 be exploited remotely?
Yes, CVE-2010-2936 can be exploited remotely by tricking a user into opening a maliciously crafted PowerPoint file.
What type of vulnerability is CVE-2010-2936?
CVE-2010-2936 is classified as a heap-based buffer overflow resulting from a short integer overflow.