Vulnerability Name: | CVE-2007-4575 (CCN-38882) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2007-12-04 | ||||||||||||||||||||||||||||||||||||
Published: | 2007-12-04 | ||||||||||||||||||||||||||||||||||||
Updated: | 2017-09-29 | ||||||||||||||||||||||||||||||||||||
Summary: | HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code via crafted database documents, related to "exposing static java methods." | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-94 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||
References: | Source: MISC Type: UNKNOWN http://bugs.gentoo.org/show_bug.cgi?id=200771 Source: MISC Type: UNKNOWN http://bugs.gentoo.org/show_bug.cgi?id=201799 Source: MITRE Type: CNA CVE-2007-4575 Source: SUSE Type: UNKNOWN SUSE-SA:2007:067 Source: CCN Type: RHSA-2007-1048 Moderate: openoffice.org Source: CCN Type: RHSA-2007-1090 Moderate: openoffice.org2 security update Source: CCN Type: RHSA-2008-0151 Moderate: JBoss Enterprise Application Platform 4.2.0CP02 security update Source: CCN Type: RHSA-2008-0158 Moderate: JBoss Enterprise Application Platform security update Source: CCN Type: RHSA-2008-0213 Moderate: JBoss Enterprise Application Platform 4.2.0CP02 security update Source: SECUNIA Type: Vendor Advisory 27914 Source: SECUNIA Type: Vendor Advisory 27916 Source: CCN Type: SA27928 OpenOffice Database Document Processing Arbitrary Java Method Execution Source: SECUNIA Type: Patch, Vendor Advisory 27928 Source: SECUNIA Type: Vendor Advisory 27931 Source: SECUNIA Type: Vendor Advisory 27972 Source: CCN Type: SA28018 Sun StarOffice/StarSuite Database Document Processing Arbitrary Java Method Execution Source: SECUNIA Type: Vendor Advisory 28018 Source: SECUNIA Type: Vendor Advisory 28039 Source: SECUNIA Type: Vendor Advisory 28286 Source: CCN Type: SA28585 Fedora update for hsqldb Source: SECUNIA Type: Vendor Advisory 28585 Source: SECUNIA Type: Vendor Advisory 30100 Source: CCN Type: SECTRACK ID: 1019041 OpenOffice Bug in HSQLDB Database Lets Remote Users Execute Arbitrary Java Code Source: CCN Type: Sun Alert ID: 103141 Manipulated Database Documents for StarOffice/StarSuite 8 May Lead to Arbitrary Code Execution Source: SUNALERT Type: Vendor Advisory 103141 Source: SUNALERT Type: UNKNOWN 200637 Source: CCN Type: ASA-2007-503 openoffice.org2 security update (RHSA-2007-1090) Source: CCN Type: ASA-2007-521 Manipulated Database Documents for StarOffice/StarSuite 8 May Lead to Arbitrary Code Execution (Sun 103141) Source: CCN Type: ASA-2008-141 JBoss Enterprise Application Platform security update (RHSA-2008-0158) Source: DEBIAN Type: UNKNOWN DSA-1419 Source: DEBIAN Type: DSA-1419 openoffice.org -- programming error Source: CCN Type: GLSA-200712-25 OpenOffice.org: User-assisted arbitrary code execution Source: GENTOO Type: UNKNOWN GLSA-200712-25 Source: MANDRIVA Type: UNKNOWN MDVSA-2008:095 Source: CCN Type: OpenOffice.org Web site Potential arbitrary code execution vulnerability in 3rd party module (HSQLDB) Source: CONFIRM Type: Patch, Vendor Advisory http://www.openoffice.org/security/cves/CVE-2007-4575.html Source: FEDORA Type: UNKNOWN FEDORA-2007-4120 Source: FEDORA Type: UNKNOWN FEDORA-2007-4172 Source: FEDORA Type: UNKNOWN FEDORA-2007-762 Source: REDHAT Type: UNKNOWN RHSA-2007:1048 Source: REDHAT Type: UNKNOWN RHSA-2007:1090 Source: REDHAT Type: UNKNOWN RHSA-2008:0151 Source: REDHAT Type: UNKNOWN RHSA-2008:0158 Source: REDHAT Type: UNKNOWN RHSA-2008:0213 Source: BID Type: Patch 26703 Source: CCN Type: BID-26703 OpenOffice HSQLDB Database Engine Unspecified Java Code Execution Vulnerability Source: SECTRACK Type: UNKNOWN 1019041 Source: CCN Type: USN-609-1 OpenOffice.org vulnerabilities Source: UBUNTU Type: UNKNOWN USN-609-1 Source: VUPEN Type: Vendor Advisory ADV-2007-4092 Source: VUPEN Type: Vendor Advisory ADV-2007-4146 Source: XF Type: UNKNOWN openoffice-hsqldb-code-execution(38882) Source: XF Type: UNKNOWN openoffice-hsqldb-code-execution(38882) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10153 Source: FEDORA Type: UNKNOWN FEDORA-2007-4171 Source: FEDORA Type: UNKNOWN FEDORA-2007-4119 Source: SUSE Type: SUSE-SA:2007:067 OpenOffice_org security update | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration RedHat 8: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |