HTTP: Apache OpenOffice dBase File Handling Buffer Overflow

This signature detects attempts to exploit a known vulnerability in the Apache OpenOffice. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack. This issue affects Apache OpenOffice up to and including version 4.1.10

Affected Products

Apache openoffice

References

CVE: CVE-2021-33035

Short Name
HTTP:APACHE:OPNOFFICE-DBF-OVRFW
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Apache Buffer CVE-2021-33035 File Handling OpenOffice Overflow dBase
Release Date
10/28/2021
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3431
False Positive
Unknown
Vendors

Apache

CVSS Score

6.8

Found a potential security threat?