LWN.net Logo

openoffice.org: code execution

Package(s):openoffice.org CVE #(s):
Created:July 8, 2011 Updated:July 13, 2011
Description:

From the Debian advisory:

Will Dormann and Jared Allar discovered that the Lotus Word Pro import filter of OpenOffice.org, a full-featured office productivity suite that provides a near drop-in replacement for Microsoft(R) Office, is not properly handling object ids in the ".lwp" file format. An attacker can exploit this with a specially crafted file and execute arbitrary code with the rights of the victim importing the file.

Alerts:
Debian DSA-2275-1 2011-07-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds