LWN.net Logo

openoffice.org: integer underflow, boundary error

Package(s):openoffice.org CVE #(s):CVE-2009-0200 CVE-2009-0201
Created:September 4, 2009 Updated:May 24, 2010
Description: From the Red Hat advisory: An integer underflow flaw and a boundary error flaw, both possibly leading to a heap-based buffer overflow, were found in the way OpenOffice.org parses certain records in Microsoft Word documents. An attacker could create a specially-crafted Microsoft Word document, which once opened by an unsuspecting user, could cause OpenOffice.org to crash or, potentially, execute arbitrary code with the permissions of the user running OpenOffice.org.
Alerts:
Mandriva MDVSA-2010:105 2010-05-21
Mandriva MDVSA-2010:091 2010-05-04
Mandriva MDVSA-2010:056 2010-03-05
Mandriva MDVSA-2010:035 2010-02-11
Ubuntu USN-840-1 2009-10-01
SuSE SUSE-SR:2009:015 2009-09-15
CentOS CESA-2009:1426 2009-09-05
CentOS CESA-2009:1426 2009-09-04
Fedora FEDORA-2009-9256 2009-09-04
Red Hat RHSA-2009:1426-01 2009-09-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds