VulnerabilityModified
CVE-2010-3450
Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a ..
HIGH 9.3EPSS 10.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a .. (dot dot) in an entry in (1) an XSLT JAR filter description file, (2) an Extension (aka OXT) file, or unspecified other (3) JAR or (4) ZIP files.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 10.73% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- apache/openoffice · canonical/ubuntu linux · debian/debian linux
- Source
- secalert@redhat.com
References
- http://osvdb.org/70711Broken Link
- http://secunia.com/advisories/40775Broken Link
- http://secunia.com/advisories/42999Broken Link
- http://secunia.com/advisories/43065Broken Link
- http://secunia.com/advisories/43105Broken Link
- http://secunia.com/advisories/43118Broken Link
- http://secunia.com/advisories/60799Broken Link
- http://ubuntu.com/usn/usn-1056-1Third Party Advisory
- http://www.debian.org/security/2011/dsa-2151Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:027Broken Link
- http://www.openoffice.org/security/cves/CVE-2010-3450.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0181.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2011-0182.htmlBroken Link
- http://www.securityfocus.com/bid/46031Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1025002Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2011/0230Broken Link
- http://www.vupen.com/english/advisories/2011/0232Broken Link
- http://www.vupen.com/english/advisories/2011/0279Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=602324Issue Tracking, Patch, Third Party Advisory
- http://osvdb.org/70711Broken Link
- http://secunia.com/advisories/40775Broken Link
- http://secunia.com/advisories/42999Broken Link
- http://secunia.com/advisories/43065Broken Link
- http://secunia.com/advisories/43105Broken Link
- http://secunia.com/advisories/43118Broken Link
- http://secunia.com/advisories/60799Broken Link
- http://ubuntu.com/usn/usn-1056-1Third Party Advisory
- http://www.debian.org/security/2011/dsa-2151Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.