CVE-2010-0395
critical
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
9.3
Description
OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
Debian Affected 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 6.0 | Affected | โ |
| 5.0 | Affected | โ |
Fedora Affected 3 releases
| Version | Status | Fixed in |
|---|---|---|
| 13 | Affected | โ |
| 12 | Affected | โ |
| 11 | Affected | โ |
SUSE Affected 5 releases
| Version | Status | Fixed in |
|---|---|---|
| 11.2 | Affected | โ |
| 11.1 | Affected | โ |
| 11.0 | Affected | โ |
| 11 | Affected | โ |
| 10 | Affected | โ |
Ubuntu Affected 4 releases
| Version | Status | Fixed in |
|---|---|---|
| 10.04 | Affected | โ |
| 9.10 | Affected | โ |
| 9.04 | Affected | โ |
| 8.04 | Affected | โ |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| apache | openoffice | {"startIncluding":"2.0.0","endExcluding":"3.2.1"} | 3.2.1 |
References
- http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042468.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042529.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042534.html
- http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html
- http://secunia.com/advisories/40070
- http://secunia.com/advisories/40084
- http://secunia.com/advisories/40104
- http://secunia.com/advisories/40107
- http://secunia.com/advisories/41818
- http://secunia.com/advisories/60799
- http://ubuntu.com/usn/usn-949-1
- http://www.debian.org/security/2010/dsa-2055
- http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:221
- http://www.openoffice.org/security/cves/CVE-2010-0395.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html
- http://www.redhat.com/support/errata/RHSA-2010-0459.html
- http://www.us-cert.gov/cas/techalerts/TA10-287A.html
- http://www.vupen.com/english/advisories/2010/1350
- http://www.vupen.com/english/advisories/2010/1353
- http://www.vupen.com/english/advisories/2010/1366
- http://www.vupen.com/english/advisories/2010/1369
- http://www.vupen.com/english/advisories/2010/2905
- https://bugzilla.redhat.com/show_bug.cgi?id=574119
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11091
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.