← Vulnerability feed

Vulnerability record · CVE-2008-0320 · published 17 April 2008

CVE-2008-0320: OpenOffice.org OLE importer heap buffer overflow via crafted DocumentSummaryInformation stream

Openoffice · Openoffice.Org

OpenOffice.org before 2.4 contains a heap-based buffer overflow in its OLE importer, triggered by an OLE file with a crafted DocumentSummaryInformation stream. Successful exploitation can crash the application and potentially allow arbitrary code execution in the context of the user opening the file.

9.3 CVSS 2.0 High EPSS 57% · top 1.0% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
60References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 2.0 score of 9.3 indicates critical impact, and high EPSS probability suggests active exploitation risk, though no KEV listing or confirmed exploit references are present.

What it is

OpenOffice.org before 2.4 contains a heap-based buffer overflow in its OLE importer, triggered by an OLE file with a crafted DocumentSummaryInformation stream. Successful exploitation can crash the application and potentially allow arbitrary code execution in the context of the user opening the file.

Impact

An attacker can cause a denial of service and possibly execute arbitrary code with the privileges of the user running OpenOffice.org. This could lead to full compromise of the user's session and data.

Attack surface

The flaw is reached remotely by convincing a user to open a malicious OLE file, requiring user interaction and no authentication. The CVSS vector AV:N/AC:M/Au:N indicates network delivery with medium complexity and no authentication.

Exploitation

The vulnerability is not listed in CISA KEV, but EPSS indicates a high probability of exploitation (0.56864, 99th percentile). No public exploit references are tagged in the provided data.

What to do

  • Update OpenOffice.org to version 2.4 or later, or apply the vendor security patches referenced in the advisories.
  • For Linux distributions, apply the relevant distribution security updates (e.g., Red Hat, Debian, Ubuntu, Gentoo, Mandriva, Novell).
  • Avoid opening untrusted OLE files or documents from unknown sources in OpenOffice.org.
  • Consider disabling or restricting the OLE import functionality if not required, where configuration options allow.
  • Educate users about the risks of opening unsolicited documents and enforce email attachment filtering.

Detection

  • Monitor for crashes or abnormal termination of OpenOffice.org processes, especially when opening OLE files.
  • Use endpoint detection to flag suspicious child processes spawned by OpenOffice.org, which may indicate code execution.
  • Inspect network traffic or email gateways for OLE files with malformed DocumentSummaryInformation streams.
  • Review system logs for exploitation attempts or unusual file access patterns related to OpenOffice.org.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=694
http://secunia.com/advisories/29844 Vendor Advisory
http://secunia.com/advisories/29852 Vendor Advisory
http://secunia.com/advisories/29864 Vendor Advisory
http://secunia.com/advisories/29871 Vendor Advisory
http://secunia.com/advisories/29910 Vendor Advisory
http://secunia.com/advisories/29913 Vendor Advisory
http://secunia.com/advisories/29987 Vendor Advisory
http://secunia.com/advisories/30100 Vendor Advisory
http://secunia.com/advisories/30179 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200805-16.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-26-231642-1
http://www.debian.org/security/2008/dsa-1547
http://www.mandriva.com/security/advisories?name=MDVSA-2008:090
http://www.mandriva.com/security/advisories?name=MDVSA-2008:095
http://www.novell.com/linux/security/advisories/2008_23_openoffice.html
http://www.openoffice.org/security/bulletin.html
http://www.openoffice.org/security/cves/CVE-2007-4770.html
http://www.openoffice.org/security/cves/CVE-2007-5745.html
http://www.openoffice.org/security/cves/CVE-2008-0320.html
http://www.redhat.com/support/errata/RHSA-2008-0175.html
http://www.redhat.com/support/errata/RHSA-2008-0176.html Vendor Advisory
http://www.securityfocus.com/bid/28819
http://www.securitytracker.com/id?1019890
http://www.ubuntu.com/usn/usn-609-1
http://www.vupen.com/english/advisories/2008/1253/references Vendor Advisory
http://www.vupen.com/english/advisories/2008/1375/references Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/41860
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10318
https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00448.html
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=694
http://secunia.com/advisories/29844 Vendor Advisory
http://secunia.com/advisories/29852 Vendor Advisory
http://secunia.com/advisories/29864 Vendor Advisory
http://secunia.com/advisories/29871 Vendor Advisory
http://secunia.com/advisories/29910 Vendor Advisory
http://secunia.com/advisories/29913 Vendor Advisory
http://secunia.com/advisories/29987 Vendor Advisory
http://secunia.com/advisories/30100 Vendor Advisory
http://secunia.com/advisories/30179 Vendor Advisory

Track CVE-2008-0320 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-3570Openoffice.org vulnerabilityUnspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in VulnDisco …EPSS 1.5%9.3CVE-2010-2935Openoffice.org vulnerabilitysimpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary …EPSS 7.1%9.3CVE-2010-2936Openoffice.org vulnerabilityInteger overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of se…EPSS 7.1%9.3CVE-2009-3571Openoffice.org memory buffer overflow vulnerabilityUnspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco …EPSS 1.3%9.3CVE-2009-0200Openoffice.org vulnerabilityInteger underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code vi…EPSS 6.7%9.3CVE-2009-0201Openoffice.org memory buffer overflow vulnerabilityHeap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrar…EPSS 6.7%9.3CVE-2009-0259Openoffice.org vulnerabilityThe Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary …EPSS 7.5%9.3CVE-2008-2237Openoffice.org memory buffer overflow vulnerabilityHeap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file associat…EPSS 6.1%

Source: NIST National Vulnerability Database (record CVE-2008-0320), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.