CVE-2010-0395 describes a critical vulnerability in OpenOffice.org versions 2.x and 3.0 prior to 3.2.1, affecting various distributions including Apache, Canonical, Debian, Fedora, OpenSUSE, and SUSE. This flaw allows remote attackers to bypass Python macro security and execute arbitrary code through a specially crafted OpenDocument Text (ODT) file, triggered when the macro directory structure is previewed. With a CVSS score of 9.3, this vulnerability is highly severe, requiring user interaction (AC:M) but allowing remote exploitation (AV:N) with complete confidentiality, integrity, and availability impacts (C:C/I:C/A:C). Despite its high severity and EPSS score, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:* | ||
9.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:* | ||
9.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:* | ||
10.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
openoffice.org Execution of Python code when browsing macros
Jun 5, 2010Security vulnerability in OpenOffice.org related to python scripting
Security vulnerability in OpenOffice.org related to python scripting
Security vulnerability in OpenOffice.org related to python scripting
Security vulnerability in OpenOffice.org related to python scripting