Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian 5.0: DSA-2099-1 Critical: OpenOffice.org Buffer Overflow

debian
Calendar Grey August 30, 2010
Debian Logo
Ubuntu Security Notice USN-5432-1 addresses severe memory corruption in LibreOffice. Upgrade immediately to safeguard your environment.
Charlie Miller has discovered two vulnerabilities in OpenOffice.org Impress, which can be exploited by malicious people to compromise a user's system and execute arbitrary code

Summary

Charlie Miller has discovered two vulnerabilities in OpenOffice.org
Impress, which can be exploited by malicious people to compromise a
user's system and execute arbitrary code.

1) An integer truncation error when parsing certain content can be
exploited to cause a heap-based buffer overflow via a specially
crafted file.

2) A short integer overflow error when parsing certain content can
be exploited to cause a heap-based buffer overflow via a specially
crafted file.

For the stable distribution (lenny) these problems have been fixed in
version 2.4.1+dfsg-1+lenny8.

For the testing (squeeze) and unstable (sid) distributions these
problems have been fixed in version 3.2.1-6.

We recommend that you upgrade your openoffice.org packages.


Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given at the end of this advisory:

...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: openoffice.org
CVE ID: CVE-2010-2935 CVE-2010-2936

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here