7.5
CVSSv2

CVE-2008-3437

Published: 01/08/2008 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

OpenOffice.org (OOo) prior to 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle malicious users to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

Vulnerable Product Search on Vulmon Subscribe to Product

openoffice openoffice.org 2.0

openoffice openoffice.org 2.0.2

openoffice openoffice.org 2.0.3

openoffice openoffice.org 2.0.4

openoffice openoffice.org 1.1.5