Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Ubuntu 10.04 LTS USN-1496-1 Critical: OpenOffice.org Buffer Overflow

ubuntu
Calendar Grey July 3, 2012
Scroller Ubuntu
OpenOffice suite flaws could lead to user disruptions and unauthorized code execution. Ensure your software is updated to reduce these threats.
OpenOffice.org could be made to crash or potentially run programs as your login if it opened a specially crafted file.

Summary

OpenOffice.org could be made to crash or potentially run programs as your

login if it opened a specially crafted file.

Software Description:

- openoffice.org: Office productivity suite

Details:

A stack-based buffer overflow was discovered in the Lotus Word Pro import

filter in OpenOffice.org. The default compiler options for affected

releases should reduce the vulnerability to a denial of service.

(CVE-2011-2685)

Huzaifa Sidhpurwala discovered that OpenOffice.org could be made to crash

if it opened a specially crafted Word document. (CVE-2011-2713)

Integer overflows were discovered in the graphics loading code of several

different image types. If a user were tricked into opening a specially

crafted file, an attacker could cause OpenOffice.org to crash or possibly

execute arbitrary code with the privileges of the user invoking the

program. (CVE-2012-1149)

Sven Jacobi discovered an integer overflow when processing Escher graphics

records. If a user were ...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
  openoffice.org-core             1:3.2.0-7ubuntu4.3

After a standard system update you need to restart OpenOffice.org to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1496-1

CVE-2011-2685, CVE-2011-2713, CVE-2012-1149, CVE-2012-2334

Severity
critical
Lowest
Low
Medium
High
Critical

July 02, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.