CVE-2010-3453: Buffer Overflow
A heap-based buffer overflow was found in the way OpenOffice.org imported Microsoft Word Binary File Format (.DOC) files with certain user defined list styles (WW8). If a user opened a specially-crafted DOC file in OpenOffice.org suite tool (oowriter), it could lead to denial of service (oowriter executable crash), or possibly, execute arbitrary code with the privileges of the user running OpenOffice.org Writer.
References: [1] http://www.cs.brown.edu/people/drosenbe/research.html
Acknowledgements:
Red Hat would like to thank OpenOffice.org for reporting this issue. Upstream acknowledges Dan Rosenberg of Virtual Security Research as the original reporter.
Other sources
The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3453?
CVE-2010-3453 is classified as a major vulnerability due to its potential to cause a heap-based buffer overflow leading to denial of service.
How do I fix CVE-2010-3453?
To fix CVE-2010-3453, users should update to a patched version of Apache OpenOffice or their relevant Linux distribution that mitigates this vulnerability.
Which versions are affected by CVE-2010-3453?
CVE-2010-3453 affects versions of Apache OpenOffice from 2.0.0 to 3.3.0 and specific versions of Debian and Ubuntu Linux.
What is the impact of exploiting CVE-2010-3453?
Exploiting CVE-2010-3453 can lead to a denial of service, causing the OpenOffice.org tool to crash when opening specially-crafted DOC files.
Is there a workaround for CVE-2010-3453 if I cannot update?
As a temporary workaround for CVE-2010-3453, users should avoid opening untrusted or suspicious DOC files until the software can be updated.