Important: openoffice.org security updateOpenOffice.org is an office productivity suite that includes desktopapplications such as a word processor, spreadsheet, presentation manager,formula editor, and drawing program.Multiple heap overflows and an integer underflow were found in the QuattroPro(R) import filter. An attacker could create a carefully crafted QuattroPro file that could cause OpenOffice.org to crash or possibly executearbitrary code if the file was opened by a victim. (CVE-2007-5745,CVE-2007-5747)A heap overflow flaw was found in the EMF parser. An attacker could createa carefully crafted EMF file that could cause OpenOffice.org to crash orpossibly execute arbitrary code if the malicious EMF image was added to adocument or if a document containing the malicious EMF file was opened by avictim. (CVE-2007-5746)A heap overflow flaw was found in the OLE Structured Storage file parser.(OLE Structured Storage is a format used by Microsoft Office documents.) Anattacker could create a carefully crafted OLE file that could causeOpenOffice.org to crash or possibly execute arbitrary code if the file wasopened by a victim. (CVE-2008-0320)All users of OpenOffice.org are advised to upgrade to these updatedpackages, which contain backported fixes to correct these issues.
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.
– Scott Cheney, Manager of Information Security, Sierra View Medical Center