Rapid7 Vulnerability & Exploit Database

CESA-2008:0176: RHSA-2008:0176

Back to Search

CESA-2008:0176: RHSA-2008:0176

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
04/17/2008
Created
07/25/2018
Added
03/12/2010
Modified
08/29/2017

Description

Important: openoffice.org security updateOpenOffice.org is an office productivity suite that includes desktopapplications such as a word processor, spreadsheet, presentation manager,formula editor, and drawing program.A heap overflow flaw was found in the EMF parser. An attacker could createa carefully crafted EMF file that could cause OpenOffice.org to crash orpossibly execute arbitrary code if the malicious EMF image was added to adocument or if a document containing the malicious EMF file was opened by avictim. (CVE-2007-5746)A heap overflow flaw was found in the OLE Structured Storage file parser.(OLE Structured Storage is a format used by Microsoft Office documents.) Anattacker could create a carefully crafted OLE file that could causeOpenOffice.org to crash or possibly execute arbitrary code if the file wasopened by a victim. (CVE-2008-0320)All users of OpenOffice.org are advised to upgrade to these updatedpackages, which contain backported fixes to correct these issues.

Solution(s)

  • centos-upgrade-openoffice-org
  • centos-upgrade-openoffice-org-i18n
  • centos-upgrade-openoffice-org-kde
  • centos-upgrade-openoffice-org-libs

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;