Tech

Guides
 

OpenOffice TIFF flaw affects Windows, Linux and Mac

By Liam Tung, ZDNet Australia
Wednesday, September 26, 2007 09:17 AM

Security experts have discovered TIFF-based buffer overflow vulnerabilities in OpenOffice, which could allow attackers to remotely execute code on Linux, Windows or Apple Mac-based computers.

OpenOffice versions 2.0.4 and prior are vulnerable to maliciously crafted TIFF file, which could be delivered in an e-mail attachment, published on a Web site or shared using P2P software. The next version of OpenOffice (version 2.3) arrived on 17 September and is not affected by the flaw.

The vulnerability was discovered by researchers at iDefense, who claim that the OpenOffice TIFF parsing code is flawed.

"When parsing the TIFF directory entries for certain tags, the parser uses untrusted values from the file to calculate the amount of memory to allocate. By providing specially crafted values, an integer overflow occurs in this calculation. This results in the allocation of a buffer of insufficient size, which in turn leads to a heap overflow," the iDefense team reported last Friday.

TrustDefender co-founder Andreas Baumhoff told ZDNet Asia's sister ZDNet Australia: "This vulnerability allows someone to execute malicious code on your computer. It's an OpenOffice bug so it doesn't matter what type of operating system you run, it allows you to run malicious software with the same rights as the user who runs OpenOffice."

"At this stage, it's only confirmed on Linux," said Baumhoff. "But typically it would affect all operating systems. The only difference with Linux and Windows is that home users typically run Windows as the administrator."

In June, OpenOffice users were warned about a worm called BadBunny, which was spreading in the wild through multiple operating systems including Mac OS, Windows and Linux.

At the time, Symantec's Security Response posted an advisory that said: "A new worm is being distributed within malicious OpenOffice documents. The worm can infect Windows, Linux, and Mac OS X systems. Be cautious when handling OpenOffice files from unknown sources".



WORTHWHILE?

0

0 votes
Blog

Talkback 1 comments

>>The only difference with Linux and Windows is that home users typically run Windows as the administrator."
Posted by tracyanne on Wednesday, September 26 2007 06:06 PM


Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Whitepapers/Case Studies

Downloads

Business Applications News

 
Virtualize your way to cost savings
Build an infrastructure that is flexible, scalable, and economical, as you strive to become a truly agile business.

Red Hat Outlines Its Virtualization Strategy and Roadmap for 2009
» Watch the video





Tech Jobs Now!

Tags

  1. bank
  2. business strategies & functions
  3. china
  4. cio
  5. environment
  6. financial
  7. hardware
  8. india
  9. industry
  10. information technology
  11. infrastructure / architecture management
  12. it outsourcing
  13. job
  14. leadership
  15. outsourcing
  16. revenue
  17. security
  18. software
  19. web
  20. web 2.0