CVE-2010-4643 describes a heap-based buffer overflow vulnerability in the Impress component of OpenOffice.org versions 2.x and 3.x before 3.3. This flaw allows remote attackers to trigger a denial of service or potentially execute arbitrary code by embedding a specially crafted Truevision TGA file within an ODF or Microsoft Office document. With a CVSS score of 9.3, this vulnerability is considered critical due to its network-based attack vector, medium attack complexity, and high potential for confidentiality, integrity, and availability impacts. Despite its severity, there is no evidence of active exploitation, public exploit code (e.g., Metasploit, ExploitDB), or significant community discussion surrounding this decade-old vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 3.3.0CPE matchmatch criteria | cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
OpenOffice.org: heap based buffer overflow when parsing TGA files
Jan 26, 2011Security Vulnerability in OpenOffice.org related to TGA file processing
Security Vulnerability in OpenOffice.org related to TGA file processing
Security Vulnerability in OpenOffice.org related to TGA file processing
Security Vulnerability in OpenOffice.org related to TGA file processing