Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-33035
HistorySep 23, 2021 - 12:00 a.m.

CVE-2021-33035

2021-09-2300:00:00
ubuntu.com
ubuntu.com
14
cve-2021-33035
apache openoffice
dbase
dbf
execution vulnerability
arbitrary code
stack alteration
unix

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.006

Percentile

79.4%

Apache OpenOffice opens dBase/DBF documents and shows the contents as
spreadsheets. DBF are database files with data organized in fields. When
reading DBF data the size of certain fields is not checked: the data is
just copied into local variables. A carefully crafted document could
overflow the allocated space, leading to the execution of arbitrary code by
altering the contents of the program stack. This issue affects Apache
OpenOffice up to and including version 4.1.10

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.006

Percentile

79.4%