LWN.net Logo

openoffice.org: multiple vulnerabilities

Package(s):openoffice.org CVE #(s):CVE-2009-2949 CVE-2009-2950 CVE-2009-3301 CVE-2009-3302
Created:February 12, 2010 Updated:November 8, 2010
Description: From the Red Hat advisory:

An integer overflow flaw, leading to a heap-based buffer overflow, was found in the way OpenOffice.org parsed XPM files. An attacker could create a specially-crafted document, which once opened by a local, unsuspecting user, could lead to arbitrary code execution with the permissions of the user running OpenOffice.org. Note: This flaw affects embedded XPM files in OpenOffice.org documents as well as stand-alone XPM files. (CVE-2009-2949)

An integer underflow flaw and a boundary error flaw, both possibly leading to a heap-based buffer overflow, were found in the way OpenOffice.org parsed certain records in Microsoft Word documents. An attacker could create a specially-crafted Microsoft Word document, which once opened by a local, unsuspecting user, could cause OpenOffice.org to crash or, potentially, execute arbitrary code with the permissions of the user running OpenOffice.org. (CVE-2009-3301, CVE-2009-3302)

A heap-based buffer overflow flaw, leading to memory corruption, was found in the way OpenOffice.org parsed GIF files. An attacker could create a specially-crafted document, which once opened by a local, unsuspecting user, could cause OpenOffice.org to crash. Note: This flaw affects embedded GIF files in OpenOffice.org documents as well as stand-alone GIF files. (CVE-2009-2950)

Alerts:
Mandriva MDVSA-2010:221 2010-11-05
Pardus 2010-67 2010-06-04
SuSE SUSE-SA:2010:017 2010-03-16
CentOS CESA-2010:0101 2010-02-14
CentOS CESA-2010:0101 2010-02-14
Fedora FEDORA-2010-1941 2010-02-16
Fedora FEDORA-2010-1847 2010-02-16
Ubuntu USN-903-1 2010-02-24
Debian DSA-1995-1 2010-02-12
Red Hat RHSA-2010:0101-02 2010-02-12

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds