9.3
CVSSv2

CVE-2010-0395

Published: 10/06/2010 Updated: 07/02/2022
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

OpenOffice.org 2.x and 3.0 prior to 3.2.1 allows user-assisted remote malicious users to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 8.04

canonical ubuntu linux 9.04

canonical ubuntu linux 9.10

canonical ubuntu linux 10.04

debian debian linux 5.0

debian debian linux 6.0

fedoraproject fedora 11

fedoraproject fedora 12

fedoraproject fedora 13

opensuse opensuse 11.0

opensuse opensuse 11.1

opensuse opensuse 11.2

suse linux enterprise desktop 10

suse linux enterprise desktop 11

apache openoffice

Vendor Advisories

OpenOfficeorg could be made to run programs as your login if it opened a specially crafted document and examined the included macros ...
It was discovered that OpenOfficeorg, a full-featured office productivity suite that provides a near drop-in replacement for Microsoft® Office, is not properly handling python macros embedded in an office document This allows an attacker to perform user-assisted execution of arbitrary code in certain use cases of the python macro viewer componen ...