WRITEUP

WRITEUP
Exploit for CVE-2021-33035 - Apache OpenOffice <4.1.10 - RCE
AI Analysis

This patch introduces length validation checks for various data types (TIMESTAMP, INTEGER, DOUBLE, DATE, BIT) in Apache OpenOffice's dBase driver to prevent potential memory corruption or out-of-bounds read/write vulnerabilities. The fix ensures that the actual data length matches the expected length for each type before processing.

Attack Type
other
Complexity
moderate
Reliability
reliable
MITRE ATT&CK
T1190 - Exploit Public-Facing Application
Loading exploit code...
Download ZIP Password: eip
Vulnerability
CVE-2021-33035
Apache OpenOffice <4.1.10 - RCE
HIGH
CVSS 7.8