Charlie Miller has discovered two vulnerabilities in OpenOffice.org
Impress, which can be exploited by malicious people to compromise a
user's system and execute arbitrary code.
1) An integer truncation error when parsing certain content can be
exploited to cause a heap-based buffer overflow via a specially
crafted file.
2) A short integer overflow error when parsing certain content can
be exploited to cause a heap-based buffer overflow via a specially
crafted file.
For the stable distribution (lenny) these problems have been fixed in
version 2.4.1+dfsg-1+lenny8.
For the testing (squeeze) and unstable (sid) distributions these
problems have been fixed in version 3.2.1-6.
We recommend that you upgrade your openoffice.org packages.
Upgrade Instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given at the end of this advisory:
...
Get the latest Linux and open source security news straight to your inbox.