simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an "integer truncation error."
Advisories
Source ID Title
Debian DSA Debian DSA DSA-2099-1 New OpenOffice.org packages fix arbitrary code execution
EUVD EUVD EUVD-2010-2939 simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an "integer truncation error."
Ubuntu USN Ubuntu USN USN-1056-1 OpenOffice.org vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html cve-icon cve-icon
http://secunia.com/advisories/40775 cve-icon cve-icon
http://secunia.com/advisories/41052 cve-icon cve-icon
http://secunia.com/advisories/41235 cve-icon cve-icon
http://secunia.com/advisories/42927 cve-icon cve-icon
http://secunia.com/advisories/43105 cve-icon cve-icon
http://secunia.com/advisories/60799 cve-icon cve-icon
http://securityevaluators.com/files/papers/CrashAnalysis.pdf cve-icon cve-icon
http://ubuntu.com/usn/usn-1056-1 cve-icon cve-icon
http://www.debian.org/security/2010/dsa-2099 cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2010:221 cve-icon cve-icon
http://www.openoffice.org/security/cves/CVE-2010-2935_CVE-2010-2936.html cve-icon cve-icon
http://www.openoffice.org/servlets/ReadMsg?list=dev&msgNo=27690 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2010/08/11/1 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2010/08/11/4 cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2010-0643.html cve-icon cve-icon
http://www.securitytracker.com/id?1024352 cve-icon cve-icon
http://www.securitytracker.com/id?1024976 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/2003 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/2149 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/2228 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/2905 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0150 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0230 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0279 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=622529 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2010-2935 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12063 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2010-2935 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T02:46:48.941Z

Reserved: 2010-08-04T00:00:00

Link: CVE-2010-2935

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2010-08-25T20:00:17.643

Modified: 2025-04-11T00:51:21.963

Link: CVE-2010-2935

cve-icon Redhat

Severity : Important

Publid Date: 2010-07-26T00:00:00Z

Links: CVE-2010-2935 - Bugzilla

cve-icon OpenCVE Enrichment

No data.