OpenOffice Multiple Heap Based Buffer Overflow Vulnerabilities
BID:28819
Info
OpenOffice Multiple Heap Based Buffer Overflow Vulnerabilities
| Bugtraq ID: | 28819 |
| Class: | Unknown |
| CVE: |
CVE-2007-5745 CVE-2007-5746 CVE-2007-5747 CVE-2008-0320 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2008 12:00AM |
| Updated: | Apr 13 2015 09:22PM |
| Credit: | OpenOffice and an anonymous researcher working with iDefense |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE Suse Linux Enterprise Desktop 10 SP1 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc Sun StarOffice 7.0 Sun StarOffice 8.0 Sun StarOffice 8 Update 7 Sun StarOffice 8 Update 6 Sun StarOffice 7.0 PP9 Sun StarOffice 7.0 PP10 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux Desktop 9.0 Redhat Fedora 7 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux Optional Productivity Application 5 server Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Desktop 4.0 Redhat Desktop 3.0 OpenOffice OpenOffice 2.3.1 OpenOffice OpenOffice 2.3 OpenOffice OpenOffice 2.2.1 OpenOffice OpenOffice 2.2 OpenOffice OpenOffice 2.0.4 OpenOffice OpenOffice 2.0.3 -1 OpenOffice OpenOffice 2.0.3 OpenOffice OpenOffice 2.0.2 OpenOffice OpenOffice 2.0.1 OpenOffice OpenOffice 2.0 Beta OpenOffice OpenOffice 1.1.52 OpenOffice OpenOffice 1.1.51 OpenOffice OpenOffice 1.1.5 OpenOffice OpenOffice 1.1.4 OpenOffice OpenOffice 1.1.3 OpenOffice OpenOffice 1.1.2 OpenOffice OpenOffice 1.1.1 OpenOffice OpenOffice 1.0.3 OpenOffice OpenOffice 1.0.2 OpenOffice OpenOffice 1.0.1 OpenOffice OpenOffice 2.2 OpenOffice OpenOffice 2.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Interactive Response 3.0 Avaya Interactive Response 2.0 |
| Not Vulnerable: |
OpenOffice OpenOffice 2.4 |
Discussion
OpenOffice Multiple Heap Based Buffer Overflow Vulnerabilities
OpenOffice is prone to multiple remote heap-based buffer-overflow vulnerabilities because of errors in processing certain files.
Remote attackers can exploit these issues by enticing victims into opening maliciously crafted ODF, Quattro Pro, EMF, or OLE files.
Successful exploits may allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely result in a denial of service.
The issues affect OpenOffice 2 prior to 2.4. The OLE and EMF file issues also affect OpenOffice 1.1.
OpenOffice is prone to multiple remote heap-based buffer-overflow vulnerabilities because of errors in processing certain files.
Remote attackers can exploit these issues by enticing victims into opening maliciously crafted ODF, Quattro Pro, EMF, or OLE files.
Successful exploits may allow attackers to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely result in a denial of service.
The issues affect OpenOffice 2 prior to 2.4. The OLE and EMF file issues also affect OpenOffice 1.1.
Exploit / POC
OpenOffice Multiple Heap Based Buffer Overflow Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available for CVE-2008-0320:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available for CVE-2008-0320:
Solution / Fix
OpenOffice Multiple Heap Based Buffer Overflow Vulnerabilities
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
OpenOffice Multiple Heap Based Buffer Overflow Vulnerabilities
References:
References:
- Multiple Vendor OpenOffice EMF EMR_BITBLT Record Integer Overflow Vulnerability (iDefense Labs)
- Multiple Vendor OpenOffice OLE DocumentSummaryInformation Heap Overflow Vulnerab (iDefense Labs)
- Multiple Vendor OpenOffice QPRO File Parsing Integer Underflow Vulnerability (iDefense Labs)
- Multiple Vendor OpenOffice QPRO Multiple Heap Overflow Vulnerabilities (iDefense Labs)
- OpenOffice Homepage (OpenOffice)
- OpenOffice.org Security Team Bulletin (OpenOffice)
- iDefense Security Advisory 04.17.08: Multiple Vendor OpenOffice EMF EMR_BITBLT R (iDefense Labs
) - iDefense Security Advisory 04.17.08: Multiple Vendor OpenOffice OLE DocumentSumm (iDefense Labs
) - iDefense Security Advisory 04.17.08: Multiple Vendor OpenOffice QPRO File Parsin (iDefense Labs
) - iDefense Security Advisory 04.17.08: Multiple Vendor OpenOffice QPRO Multiple He (iDefense Labs
) - 231601: Security Vulnerability With Quattro Pro Files in StarOffice 8/StarSuite (Sun)
- 231642: Security Vulnerability for OLE Files in StarOffice 7 and 8, StarSuite 7 (Sun)
- 231661: Manipulated EMF Files May Lead to Heap Overflows and Arbitrary Code Exec (Sun Microsystems)
- ASA-2008-185 (Avaya)
- ASA-2008-192Security Vulnerability for OLE Files in StarOffice 7 and 8, StarSuit (Avaya)
- CVE-2007-4770/4771 - Manipulated ODF text documents containing XForms can lead t (OpenOffice)
- CVE-2007-5745/5747 - Manipulated Quattro Pro files can lead to heap overflows an (OpenOffice)
- CVE-2007-5746 - Manipulated EMF files can lead to heap overflows and arbitrary c (OpenOffice)
- CVE-2008-0320 - Manipulated OLE files can lead to heap overflows and arbitrary c (OpenOffice)
- RHSA-2008:0175-7 openoffice.org security update (Red Hat)
- RHSA-2008:0176-7 openoffice.org security update (Red Hat)