Vulnerability Details CVE-2008-3437
OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.4%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2008-3437
-
cpe:2.3:a:openoffice:openoffice.org:1.1.5
-
cpe:2.3:a:openoffice:openoffice.org:2.0
-
cpe:2.3:a:openoffice:openoffice.org:2.0.2
-
cpe:2.3:a:openoffice:openoffice.org:2.0.3
-
cpe:2.3:a:openoffice:openoffice.org:2.0.4