There's been found a vulnerability in OpenOffice.org software file handling. Vulnerability may allow a remote unprivileged user who provides a OpenOffice.org document that is opened by a local user to execute arbitrary commands on the system with the privileges of the user running OpenOffice.org.
Vulnerable are OpenOffice.org versions between 2.0 and 2.4. Users of these versions are instructed to update their software to version 2.4.1.
More information here.
Showing posts with label Open Office. Show all posts
Showing posts with label Open Office. Show all posts
Thursday, June 12, 2008
Friday, April 18, 2008
Vulnerabilities in Open Office software
Multiple vulnerabilities have been identified in Open Office software, which could be exploited by attackers to cause a denial of service or compromise an affected system. These issues are caused by heap overflow and corruption errors when processing specially crafted ODF text documents with XForms, or when handling malformed Quattro Pro, EMF or OLE files, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into opening a specially crafted document.
Vulnerable versions are all versions beyond 2.4 version so users are instructed to update their versions to the latest one.
Release Notes of Open Office 2.4 version can be read here
Vulnerable versions are all versions beyond 2.4 version so users are instructed to update their versions to the latest one.
Release Notes of Open Office 2.4 version can be read here
Subscribe to:
Posts (Atom)