Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Fedora: 2004-102 Critical: OpenOffice Format String Issue - Arbitrary Code

fedora
Calendar Grey April 15, 2004
Dist Fedora Esm H88
Crucial update for Fedora LibreOffice tackles multiple format string flaws aimed at reducing exposure to possible arbitrary code execution threats.
This patch fixes vulnerabilities that may allow execution of arbitrary code, as well as other bugfixes.

Summary

OpenOffice.org is an Open Source, community-developed, multi-platform

office productivity suite. It includes the key desktop applications,

such as a word processor, spreadsheet, presentation manager, formula

editor and drawing program, with a user interface and feature set

similar to other office suites. Sophisticated and flexible,

OpenOffice.org also works transparently with a variety of file

formats, including Microsoft Office.

Usage: Simply type "ooffice" to run OpenOffice.org or select the

requested component (Writer, Calc, Draw, Impress, etc.) from your

desktop menu. The ooffice wrapper script will install a few files in

the user's home, if necessary.

Note that this release does not support GPC polygon clipping, but

instead uses libart to do the same thing.

The OpenOffice.org team hopes you enjoy working with OpenOffice.org!

Update Information:

This update fixes a security vulnerability in the neon included in OpenOffice.org (CAN-2004-0179). It also explicitly adds a dependency on Mozilla which has always existed. This dependency will be removed again in the next update since it appears to cause problems however. * Mon Apr 05 2004 Dan Williams <dcbw@redhat.com> 1.1.0-15

- Fix CAN-2004-0179 (neon format string vuln) - Add missing Mozilla Requires:

* Fri Mar 12 2004 Dan Williams <dcbw@redhat.com> 1.1.0-14

- Detect and use Agfa Monotype fonts - Add font replacements for Century Gothic and Verdana - Don't die when TrueType fonts have bad name table strings (RH #117440)

* Tue Feb 10 2004 Dan Williams <dcbw@redhat.com> 1.1.0-13

- Remove OOo setup menu entry - Remove some python test stuff too - Delete the ~/.openoffice/user/work link when upgrading since people seem to inadvertently wipe their home directories because of it

* Fri Feb 06 2004 Dan Williams <dcbw@redhat.com> 1.1.0-12

- Remove creation ...

Read the Full Advisory

Change Log

References

Fedora Update Notification FEDORA-2004-102 2004-04-15 Name : openoffice.org Version : 1.1.0 Release : 15 Summary : OpenOffice.org comprehensive office suite. Description : OpenOffice.org is an Open Source, community-developed, multi-platform office productivity suite. It includes the key desktop applications, such as a word processor, spreadsheet, presentation manager, formula editor and drawing program, with a user interface and feature set similar to other office suites. Sophisticated and flexible, OpenOffice.org also works transparently with a variety of file formats, including Microsoft Office. Usage: Simply type "ooffice" to run OpenOffice.org or select the requested component (Writer, Calc, Draw, Impress, etc.) from your desktop menu. The ooffice wrapper script will install a few files in the user's home, if necessary. Note that this release does not support GPC polygon clipping, but instead uses libart to do the same thing. The OpenOffice.org team hopes you enjoy working with OpenOffice.org!

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Name: openoffice.org
Version: 1.1.0
Release: 15
Summary: OpenOffice.org comprehensive office suite.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here