Showing posts with label OpenOffice. Show all posts
Showing posts with label OpenOffice. Show all posts

Wednesday, August 15, 2012

Vulnerability In OpenOffice And LibreOffice

There has been found a vulnerability in OpenOffice And LibreOffice. The vulnerability (CVE-2012-2665) may allow an attacker to execute arbitrary code in vulnerable system.

Affected versions:
-OpenOffice 3.4.0 and earlier versions
-LibreOffice prior version 3.5.5

Fresh version for LibreOffice is available here. OpenOffice fix is still pending and will be found here when available.

Thursday, January 27, 2011

OpenOffice 3.3 Released

OpenOffice.org has released a new version of OpenOffice. The fresh version contains fixes for nine vulnerabilities:
- CVE-2010-2935 / CVE-2010-2936: Security Vulnerability in OpenOffice.org related to PowerPoint document processing
- CVE-2010-3450: Security Vulnerability in OpenOffice.org related to Extensions and filter package files
- CVE-2010-3451 / CVE-2010-3452: Security Vulnerability in OpenOffice.org related to RTF document processing
- CVE-2010-3453 / CVE-2010-3454: Security Vulnerability in OpenOffice.org related to Word document processing
- CVE-2010-3689: Insecure LD_LIBRARY_PATH usage in OpenOffice.org shell scripts
- CVE-2010-3702 / CVE-2010-3704: Security Vulnerability in OpenOffice.org's PDF Import extension resulting from 3rd party library XPDF
- CVE-2010-4008 / CVE-2010-4494: Possible Security Vulnerability in OpenOffice.org resulting from 3rd party library LIBXML2
- CVE-2010-4253: Security Vulnerability in OpenOffice.org related to PNG file processing
- CVE-2010-4643: Security Vulnerability in OpenOffice.org related to TGA file processing



More information about OpenOffice security fixes can be found here and about other changes can be read from Release Notes. OpenOffice 3.3 can be downloaded here.

Sunday, June 6, 2010

OpenOffice 3.2.1 Available

OpenOffice.org has released a new version of OpenOffice. The fresh version contains fixes for two vulnerabilities:
-CVE-2009-3555: OpenOffice.org 2 and 3 may be affected by the TLS/SSL Renegotiation Issue in 3rd Party Libraries
-CVE-2010-0395: Security vulnerability in OpenOffice.org related to python scripting

More information about OpenOffice security fixes can be found here and about other changes can be read from Release Notes. OpenOffice 3.2.1 can be downloaded here.

Monday, February 15, 2010

OpenOffice 3.2 Released

OpenOffice.org has released a new version of OpenOffice. The fresh version contains fixes for several vulnerabilities:
* CVE-2006-4339: Potential vulnerability from 3rd party libxml2 libraries
* CVE-2009-0217: Potential vulnerability from 3rd party libxmlsec libraries
* CVE-2009-2493: OpenOffice.org 3 for Windows bundles a vulnerable version of MSVC Runtime
* CVE-2009-2949: Potential vulnerability related to XPM file processing
* CVE-2009-2950: Potential vulnerability related to GIF file processing
* CVE-2009-3301/2: Potential vulnerability related to MS-Word document processing

More information can be found here. OpenOffice 3.2 can be downloaded here.

Wednesday, October 29, 2008

Vulnerabilities In OpenOffice 2.x Software

There has been found two vulnerabilities in OpenOffice software. The vulnerabilities are related to WMF and EMF file processing. Due to the lack of proper checks it's possible to cause buffer overflow in target system. Vulnerabilities can be exploited by attracting a user to open specially crafted StarOffice/StarSuite document. Successful exploitation of the vulnerabilities may allow execution of arbitrary code.

Affected are all OpenOffice 2.x versions prior 2.4.2. OpenOffice users are instructed to update their version to 2.4.2 or 3.0.0 which is not affected by the vulnerabilities.

More information on the vulnerabilities:
CVE-2008-2237
CVE-2008-2238