GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Fri Jul 28, 2006 10:26 pm Post subject: [ GLSA 200607-12 ] OpenOffice.org: Multiple vulnerabilities |
|
|
Gentoo Linux Security Advisory
Title: OpenOffice.org: Multiple vulnerabilities (GLSA 200607-12)
Severity: normal
Exploitable: remote
Date: July 28, 2006
Bug(s): #138545
ID: 200607-12
Synopsis
OpenOffice.org is affected by three security vulnerabilities which can be exploited to allow the execution of arbitrary code by a remote attacker.
Background
OpenOffice.org is an open source office productivity suite, including word processing, spreadsheet, presentation, drawing, data charting, formula editing, and file conversion facilities.
Affected Packages
Package: app-office/openoffice
Vulnerable: < 2.0.3
Unaffected: >= 2.0.3
Architectures: All supported architectures
Package: app-office/openoffice-bin
Vulnerable: < 2.0.3
Unaffected: >= 2.0.3
Architectures: All supported architectures
Description
Internal security audits by OpenOffice.org have discovered three security vulnerabilities related to Java applets, macros and the XML file format parser. - Specially crafted Java applets can break through the "sandbox".
- Specially crafted macros make it possible to inject BASIC code into documents which is executed when the document is loaded.
- Loading a malformed XML file can cause a buffer overflow.
Impact
An attacker might exploit these vulnerabilities to escape the Java sandbox, execute arbitrary code or BASIC code with the permissions of the user running OpenOffice.org.
Workaround
Disabling Java applets will protect against the vulnerability in the handling of Java applets. There are no workarounds for the macro and file format vulnerabilities.
Resolution
All OpenOffice.org users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=app-office/openoffice-2.0.3" |
References
OpenOffice.org Security Bulletin 2006-06-29
CVE-2006-2199
CVE-2006-2198
CVE-2006-3117 |
|