9.3 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
0.924 High
EPSS
Percentile
99.0%
CentOS Errata and Security Advisory CESA-2008:0176
OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.
A heap overflow flaw was found in the EMF parser. An attacker could create
a carefully crafted EMF file that could cause OpenOffice.org to crash or
possibly execute arbitrary code if the malicious EMF image was added to a
document or if a document containing the malicious EMF file was opened by a
victim. (CVE-2007-5746)
A heap overflow flaw was found in the OLE Structured Storage file parser.
(OLE Structured Storage is a format used by Microsoft Office documents.) An
attacker could create a carefully crafted OLE file that could cause
OpenOffice.org to crash or possibly execute arbitrary code if the file was
opened by a victim. (CVE-2008-0320)
All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported fixes to correct these issues.
Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2008-April/076986.html
https://lists.centos.org/pipermail/centos-announce/2008-April/076987.html
https://lists.centos.org/pipermail/centos-announce/2008-April/077012.html
https://lists.centos.org/pipermail/centos-announce/2008-April/077013.html
Affected packages:
openoffice.org
openoffice.org-i18n
openoffice.org-kde
openoffice.org-libs
Upstream details at:
https://access.redhat.com/errata/RHSA-2008:0176
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
CentOS | 3 | i386 | openoffice.org | <Β 1.1.2-41.2.0.EL3 | openoffice.org-1.1.2-41.2.0.EL3.i386.rpm |
CentOS | 3 | i386 | openoffice.org-i18n | <Β 1.1.2-41.2.0.EL3 | openoffice.org-i18n-1.1.2-41.2.0.EL3.i386.rpm |
CentOS | 3 | i386 | openoffice.org-libs | <Β 1.1.2-41.2.0.EL3 | openoffice.org-libs-1.1.2-41.2.0.EL3.i386.rpm |
CentOS | 3 | i386 | openoffice.org | <Β 1.1.2-41.2.0.EL3 | openoffice.org-1.1.2-41.2.0.EL3.i386.rpm |
CentOS | 3 | i386 | openoffice.org-i18n | <Β 1.1.2-41.2.0.EL3 | openoffice.org-i18n-1.1.2-41.2.0.EL3.i386.rpm |
CentOS | 3 | i386 | openoffice.org-libs | <Β 1.1.2-41.2.0.EL3 | openoffice.org-libs-1.1.2-41.2.0.EL3.i386.rpm |
CentOS | 4 | i386 | openoffice.org | <Β 1.1.5-10.6.0.3.EL4 | openoffice.org-1.1.5-10.6.0.3.EL4.i386.rpm |
CentOS | 4 | i386 | openoffice.org-i18n | <Β 1.1.5-10.6.0.3.EL4 | openoffice.org-i18n-1.1.5-10.6.0.3.EL4.i386.rpm |
CentOS | 4 | i386 | openoffice.org-kde | <Β 1.1.5-10.6.0.3.EL4 | openoffice.org-kde-1.1.5-10.6.0.3.EL4.i386.rpm |
CentOS | 4 | i386 | openoffice.org-libs | <Β 1.1.5-10.6.0.3.EL4 | openoffice.org-libs-1.1.5-10.6.0.3.EL4.i386.rpm |