Lucene search

K
redhatRedHatRHSA-2008:0939
HistoryNov 05, 2008 - 12:00 a.m.

(RHSA-2008:0939) Important: openoffice.org security update

2008-11-0500:00:00
access.redhat.com
16

0.124 Low

EPSS

Percentile

95.4%

OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

SureRun Security Team discovered an integer overflow flaw leading to a heap
buffer overflow in the Windows Metafile (WMF) image format parser. An
attacker could create a carefully crafted document containing a malicious
WMF file that could cause OpenOffice.org to crash, or, possibly, execute
arbitrary code if opened by a victim. (CVE-2008-2237)

Multiple integer overflow flaws were found in the Enhanced Windows Metafile
(EMF) parser. An attacker could create a carefully crafted document
containing a malicious EMF file that could cause OpenOffice.org to crash,
or, possibly, execute arbitrary code if opened by a victim. (CVE-2008-2238)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported patches that correct these issues.