OpenOffice.org Documents Parsing Code Execution Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in OpenOffice.org, which could be exploited by attackers to compromise a vulnerable system.
1. Due to an integer underflow error when parsing certain records in a Word document table, which could allow attackers to crash an affected application or execute arbitrary code by tricking a user into opening a specially crafted Word document.
2. Due to a heap overflow error when parsing certain records in a Word document, which could allow attackers to crash an affected application or execute arbitrary code by tricking a user into opening a malicious Word document.
Impact
- Remote Code Execution
System / Technologies affected
- OpenOffice.org versions prior to 3.1.1
Solutions
- Upgrade to OpenOffice.org version 3.1.1 :
http://download.openoffice.org/index.html
Vulnerability Identifier
Source
Related Link
Share with