Vulnerability in OpenOffice Allows Code Execution When Opening a File

A vulnerability has been identified in the Apache OpenOffice office suite (CVE-2021-33035) that enables code execution when opening a specially crafted file in DBF format. The researcher who discovered the problem warned of the creation of a working exploit for the Windows platform. A patch for this vulnerability is currently available only in the project's repository, included in the test builds of OpenOffice 4.1.11. Updates for the stable branch have not yet been provided.

The issue arises from the fact that when allocating memory, OpenOffice relied on the fieldLength and fieldType values in the header of DBF files without checking the actual data type in the fields. To execute an attack, one can specify the fieldType as INTEGER, but place larger data and specify the fieldLength value that does not correspond to the size of data with the INTEGER type, leading to the tail of the data being written beyond the allocated buffer. As a result of controlled buffer overflow, the researcher was able to overwrite the return pointer from the function and, using return-oriented programming (ROP) techniques, execute their code.

When using ROP techniques, the attacker does not attempt to place their code in memory but operates with existing chunks of machine instructions in loaded libraries that end with return control instructions (typically the endings of library functions). The exploit's operation consists of constructing a chain of calls to such blocks ('gadgets') to achieve the desired functionality. For the OpenOffice exploit, code from the libxml2 library used within OpenOffice was utilized, which, unlike OpenOffice itself, was compiled without protection mechanisms like DEP (Data Execution Prevention) and ASLR (Address Space Layout Randomization).

OpenOffice developers were notified of the issue on May 4, after which a public disclosure of the vulnerability was scheduled for August 30. As the stable branch update was not ready by the deadline, the researcher postponed the disclosure of details to September 18. However, by this date, OpenOffice developers had not managed to form release 4.1.11. Notably, during the same research, a similar vulnerability was discovered in the DBF format support code in Microsoft Office Access (CVE-2021–38646), with details to be disclosed later. No issues were found in LibreOffice.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster