R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

OpenOffice hit by 'highly critical' flaw

Problems dealing with Tiff images could allow remote access

Matt Chapman, vnunet.com 18 Sep 2007
ADVERTISEMENT

A 'highly critical' flaw has been discovered in the OpenOffice suite of products that could allow hackers to access a user's system.

The vulnerability is caused by integer overflows when processing certain tags within Tiff images.

This problem could be exploited to cause heap-based buffer overflows, possibly by tricking a user into opening a specially crafted document.

Successful exploitation could allow the execution of arbitrary code and compromise a user's system, according to Secunia, which rated the vulnerability as 'highly critical'.

The vulnerabilities are reported in versions earlier than OpenOffice 2.3 and the problem can be fixed by upgrading to the latest version of the software.

Red Hat has updated its OpenOffice packages to correct the security issue in Red Hat Enterprise Linux versions 3, 4 and 5.

OpenOffice is a free office productivity suite that includes a word processor, spreadsheet, presentation manager, formula editor and drawing program.

See also:

MicrosoftVista and XP spared from most dangerous vulnerabilities  12 Sep 2007
Apple iTunesSoftware exposes users to remote code execution vulnerability  07 Sep 2007
MicrosoftVulnerability puts users at risk of arbitrary code execution  29 Aug 2007
Similar issues in Cisco and Checkpoint products, NTA Monitor warns  21 Aug 2007
Microsoft ExcelVulnerability could be exploited to compromise a user's system  16 Aug 2007
Yahoo MessengerChinese security boards reveal new vulnerability  16 Aug 2007

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
EXCEPTIONAL .NET (ASP / VB / C#) DEVELOPER – SURREY HEDGE FUND My client is a CASH RICH leading Microsoft Technology focused Hedge Fund currently experiencing unrivalled success – they need to bring on fresh ... more >
| JAM Recruitment
Position: Software Developer – Modelling / Simulations Salary: £27-37,000 Location: Luton, Bedford, Milton Keynes Apply to: a.ross@jamrecruitment.co.uk This is an excellent chance to join one of the UK’s leading Defence businesses operating at the forefront ... more >
| JAM Recruitment
Position: Software Engineer – C/C++/GUI/UML Salary: £30-40,000 Location: Leicester Apply to: a.ross@jamjobs.co.uk This is a fabulous opportunity to join a globally recognised organisation working as part of a team taking innovative and cutting edge solutions ... more >
| JAM Recruitment
Position: Embedded Software / Systems Engineer Salary: £25-40,000 Location: Barrow, Cumbria, Carlisle, Lake District Apply to: a.ross@jamrecruitment.co.uk (inc salary expectations, availability and notice period) This is an exciting opportunity to join one of the UKs ... more >
More job opportunities