PublicDateAtUSN: 2011-01-28 Candidate: CVE-2010-4253 PublicDate: 2011-01-28 22:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4253 https://ubuntu.com/security/notices/USN-1056-1 Description: Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in an ODF or Microsoft Office document, as demonstrated by a PowerPoint (aka PPT) document. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Marc Schoenefeld Assigned-to: CVSS: Patches_openoffice.org: upstream_openoffice.org: released (3.3) dapper_openoffice.org: ignored (reached end-of-life) hardy_openoffice.org: released (1:2.4.1-1ubuntu2.5) karmic_openoffice.org: released (1:3.1.1-5ubuntu1.3) lucid_openoffice.org: released (1:3.2.0-7ubuntu4.2) maverick_openoffice.org: released (1:3.2.1-7ubuntu1.1) devel_openoffice.org: DNE Patches_libreoffice: upstream_libreoffice: released (3.3) dapper_libreoffice: DNE hardy_libreoffice: DNE karmic_libreoffice: DNE lucid_libreoffice: DNE maverick_libreoffice: DNE devel_libreoffice: not-affected