CVE-2010-0136
Summary
| CVE | CVE-2010-0136 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-02-16 19:30:00 UTC |
| Updated | 2023-11-07 02:05:00 UTC |
| Description | OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| ./packages/openofficeorg/3.1.1/unstable r1866: merge 1:3.1.1-15+squeeze1 |
MLIST |
www.mail-archive.com |
|
| Advisories | Mandriva |
MANDRIVA |
www.mandriva.com |
|
| OpenOffice VBA Macro Security Controls Can Be Bypassed - SecurityTracker |
SECTRACK |
securitytracker.com |
|
| OpenOffice VBA Macro Restrictions Remote Security Bypass Vulnerability |
BID |
www.securityfocus.com |
|
| Ubuntu update for openoffice.org - Advisories - Community |
SECUNIA |
secunia.com |
|
| Debian -- Security Information -- DSA-1995-1 openoffice.org |
DEBIAN |
www.debian.org |
|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH |
VUPEN |
www.vupen.com |
|
| [security-announce] SUSE Security Announcement: OpenOffice.org (SUSE-SA: |
SUSE |
lists.opensuse.org |
|
| ./packages/openofficeorg/3.1.1/unstable r1866: merge 1:3.1.1-15+squeeze1 |
|
www.mail-archive.com |
|
| Webmail - OVH |
VUPEN |
www.vupen.com |
|
| SUSE update for OpenOffice_org - Secunia.com |
SECUNIA |
secunia.com |
|
| USN-903-1: OpenOffice.org vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|
| Red Hat | 2010-03-05 | Tomas Hoger | Not vulnerable. This issue did not affect the versions of openoffice.org as shipped with Red Hat Enterprise Linux 3, 4, or 5. |
There are currently no legacy QID mappings associated with this CVE.