LandzDown Forum

Security => Security Alerts & Briefings => Topic started by: Frands on October 29, 2008, 08:17:04 PM

Title: Vulnerability in OpenOffice
Post by: Frands on October 29, 2008, 08:17:04 PM
Hi :)

Two security holes have been discovered in the way OpenOffice  deals with Microsoft's media file formats. emf, and. wmf, according to security firm CSIS. All versions prior to OpenOffice 2.4.2 are affected by the vulnerability, which is based on heap-overflows.

The vulnerability makes it possible to run code on a client  with the same rights as the user. The vulnerability can be triggered by sending the user on the client to a specific design file, or by enticing users to click on a link, for example, an e-mail.

CSIS recommends that Open Office users upgrade as soon as possible. The two updated versions of OpenOffice, where the gaps are closed, is 2.4.2 and the new 3.0.

http://www.openoffice.org/security/cves/CVE-2008-2237.html

http://www.openoffice.org/security/cves/CVE-2008-2238.html

Download link: http://download.openoffice.org/index.html

With kind regards
Stealthzone
Title: Re: Vulnerability in OpenOffice
Post by: GR@PH;<'S on October 29, 2008, 08:20:53 PM
stealthzone,
Thaks for bringing these to the attentsion of those who have and use OpenOffice (https://www.landzdown.com/proxy.php?request=http%3A%2F%2Fwww.getsmile.com%2Femoticons%2Ffunny-smileys-68129%2Fgentleman.gif&hash=d80ac3e108b014262718502fab8674014d7559a4)

I recommended that any one using OpenOffice to go the updates

GR@PH;<'S   :Hammys pint: