An integer truncation error, leading to heap-based buffer overflow was found in the way OpenOffice.org Impress presentation application sanitized dictionary property items of the processed file. An attacker could use this flaw to create a specially-crafted Microsoft PowerPoint (PPT) file that, when opened, would cause simpress.bin executable to crash, or, possibly execute arbitrary code with the privileges of the user running the ooimpress tool.
References: [1] http://secunia.com/advisories/40775/ [2] http://securityevaluators.com/files/papers/CrashAnalysis.pdf [3] http://www.openoffice.org/servlets/ReadMsg?list=dev&msgNo=27690
CVE Request: [4] http://www.openwall.com/lists/oss-security/2010/08/11/1
A short integer overflow, leading to heap-based buffer overflow was found in the way OpenOffice.org Impress presentation aplication processed polygons in input document. An attacker could use this flaw to create a specially-crafted Microsoft PowerPoint (PPT) file that, when opened, would cause simpress.bin executable to crash, or, possibly execute arbitrary code with the privileges of the user running the ooimpress tool.
References: [1] http://secunia.com/advisories/40775/ [2] http://securityevaluators.com/files/papers/CrashAnalysis.pdf [3] http://www.openoffice.org/servlets/ReadMsg?list=dev&msgNo=27690
CVE Request: [4] http://www.openwall.com/lists/oss-security/2010/08/11/1