Vulnerability record · CVE-2008-0320 · published 17 April 2008
CVE-2008-0320: OpenOffice.org OLE importer heap buffer overflow via crafted DocumentSummaryInformation stream
Openoffice · Openoffice.Org
OpenOffice.org before 2.4 contains a heap-based buffer overflow in its OLE importer, triggered by an OLE file with a crafted DocumentSummaryInformation stream. Successful exploitation can crash the application and potentially allow arbitrary code execution in the context of the user opening the file.
Description
Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 2.0 score of 9.3 indicates critical impact, and high EPSS probability suggests active exploitation risk, though no KEV listing or confirmed exploit references are present.
What it is
OpenOffice.org before 2.4 contains a heap-based buffer overflow in its OLE importer, triggered by an OLE file with a crafted DocumentSummaryInformation stream. Successful exploitation can crash the application and potentially allow arbitrary code execution in the context of the user opening the file.
Impact
An attacker can cause a denial of service and possibly execute arbitrary code with the privileges of the user running OpenOffice.org. This could lead to full compromise of the user's session and data.
Attack surface
The flaw is reached remotely by convincing a user to open a malicious OLE file, requiring user interaction and no authentication. The CVSS vector AV:N/AC:M/Au:N indicates network delivery with medium complexity and no authentication.
Exploitation
The vulnerability is not listed in CISA KEV, but EPSS indicates a high probability of exploitation (0.56864, 99th percentile). No public exploit references are tagged in the provided data.
What to do
- Update OpenOffice.org to version 2.4 or later, or apply the vendor security patches referenced in the advisories.
- For Linux distributions, apply the relevant distribution security updates (e.g., Red Hat, Debian, Ubuntu, Gentoo, Mandriva, Novell).
- Avoid opening untrusted OLE files or documents from unknown sources in OpenOffice.org.
- Consider disabling or restricting the OLE import functionality if not required, where configuration options allow.
- Educate users about the risks of opening unsolicited documents and enforce email attachment filtering.
Detection
- Monitor for crashes or abnormal termination of OpenOffice.org processes, especially when opening OLE files.
- Use endpoint detection to flag suspicious child processes spawned by OpenOffice.org, which may indicate code execution.
- Inspect network traffic or email gateways for OLE files with malformed DocumentSummaryInformation streams.
- Review system logs for exploitation attempts or unusual file access patterns related to OpenOffice.org.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-0320 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-0320), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.