CVE-2010-0136

OpenOffice.org 2.0.4, 2.4.1, and 3.1.1 - Remote Code Execution via Crafted Document

Title source: llm
STIX 2.1

Description

OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document.

References (11)

Core 11
Core References
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2010:221
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38695
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2010/dsa-1995
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1023588
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-903-1
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00005.html
Broken Link vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0635
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/38245
Broken Link third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38921
Broken Link vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2905

Scores

EPSS 0.0813
EPSS Percentile 94.1%

Details

CWE
CWE-77
Status published
Products (9)
apache/openoffice 2.0.4
apache/openoffice 2.4.1
apache/openoffice 3.1.1
canonical/ubuntu_linux 8.04
canonical/ubuntu_linux 8.10
canonical/ubuntu_linux 9.04
canonical/ubuntu_linux 9.10
debian/debian_linux 4.0
debian/debian_linux 5.0
Published Feb 16, 2010
Tracked Since Feb 18, 2026