LWN.net Logo

openoffice.org: multiple vulnerabilities

Package(s):openoffice.org CVE #(s):CVE-2008-2237 CVE-2008-2238
Created:October 30, 2008 Updated:January 13, 2009
Description: openoffice.org has two file parser vulnerabilities. From the Debian alert:

CVE-2008-2237 The SureRun Security team discovered a bug in the WMF file parser that can be triggered by manipulated WMF files and can lead to heap overflows and arbitrary code execution.

CVE-2008-2238 An anonymous researcher working with the iDefense discovered a bug in the EMF file parser that can be triggered by manipulated EMF files and can lead to heap overflows and arbitrary code execution.

Alerts:
Ubuntu USN-677-2 2008-12-23
Gentoo 200812-13 2008-12-12
Ubuntu USN-677-1 2008-11-24
SuSE SUSE-SR:2008:026 2008-11-24
CentOS CESA-2008:0939 2008-11-05
Red Hat RHSA-2008:0939-00 2008-11-05
Fedora FEDORA-2008-9333 2008-10-31
Fedora FEDORA-2008-9313 2008-10-31
Debian DSA-1661-1 2008-10-29
Mandriva MDVSA-2009:006 2008-01-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds