[ MDVSA-2008:095 ] - Updated OpenOffice.org packages fix vul

Mandrivan turvallisuustiedotteiden tuoreimmat

[ MDVSA-2008:095 ] - Updated OpenOffice.org packages fix vul

Uusi viestiKirjoittaja dude67 » 02 Touko 2008, 21:27

Updated OpenOffice.org packages fix vulnerabilities

A vulnerability in HSQLDB before 1.8.0.9 in OpenOffice.org could
allow user-assisted remote attackers to execute arbitrary Java code
via crafted database documents (CVE-2007-4575).

A heap overflow was discovered in OpenOffice.org's EMF parser.
An attacker could create a carefully crafted EMF file that could
cause OpenOffice.org to crash or potentially execute arbitrary code
if the malicious EMF image was added to a document or if a document
containing such an EMF file was opened (CVE-2007-5746).

Multiple heap overflows and an integer underflow were discovered in the
Quattro Pro(R) import filter. An attacker could create a carefully
crafted Quattro Pro file that could cause OpenOffice.org ro crash or
potentially execute arbitraty code (CVE-2007-5745, CVE-2007-5747).

A heap overflow was discovered in the OLE Structured Storage file
parser, a format used by Microsoft Office documents. An attacker could
create a carefully crafted OLE file that could cause OpenOffice.org
to crash or potentially execute arbitrary code (CVE-2008-0320).

The updated packages have been patched to correct these issues.
Kuva
1. Mageia-1 KDE4 x86_64 (& Win7 Pro) | desktop
2. Mageia-2 KDE4 (& Win7 Home Premium) | laptop Acer 7530
3. Mageia-1 KDE4 (& Win7 Starter) | Samsung NC-10 miniläppäri
4. Mageia-1 KDE4 | serverinä toimiva desktop
Luotettavaa Linux käyttöä jo Mandriva 2006.0:sta lähtien :)
Avatar
dude67
Site Admin
 
Viestit: 2256
Liittynyt: 27 Syys 2007, 16:58
Paikkakunta: Espoo

Paluu Mandrivan turvallisuustiedotteet

Paikallaolijat

Käyttäjiä lukemassa tätä aluetta: Ei rekisteröityneitä käyttäjiä ja 53 vierailijaa

cron