OpenOffice patches file-processing flaws

By Tom Espiner, ZDNet UK
Friday, October 31, 2008 10:41 AM

OpenOffice has updated its productivity suite to patch two flaws that could lead to arbitrary code execution.

OpenOffice.org is commonly found on Linux Netbooks and is Ubuntu's standard spreadsheet, word processor, database and presentation package.

The flaws affect all versions of OpenOffice.org prior to 2.4.2. One flaw, detailed in security alert CVE-2008-2237, lies in the way OpenOffice 2.x processes WMF files. The other flaw, detailed in CVE-2008-2238, is due to the way OpenOffice 2.x processes EMF files.

Both vulnerabilities may allow a remote unprivileged user who tricks a local user into opening a manipulated a StarOffice or StarSuite document to execute arbitrary commands on the system. No working exploit is known at the moment for either flaw.

Some Netbook makers have turned to OpenOffice's productivity applications for inclusion on models powered by Linux. The Asus Eee comes with OpenOffice 2.0 and both Acer's Aspire One and Everex's Cloudbook come with version 2.3.

There are no workarounds. Both issues are addressed in OpenOffice.org 2.4.2. OpenOffice.org 3.0 is not affected by these vulnerabilities.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web