Lucene search

K
ubuntuUbuntuUSN-444-1
HistoryMar 27, 2007 - 12:00 a.m.

OpenOffice.org vulnerabilities

2007-03-2700:00:00
ubuntu.com
35

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.55

Percentile

97.7%

Releases

  • Ubuntu 6.10
  • Ubuntu 6.06
  • Ubuntu 5.10

Details

A stack overflow was discovered in OpenOffice.org’s StarCalc parser. If
a user were tricked into opening a specially crafted document, a remote
attacker could execute arbitrary code with user privileges.
(CVE-2007-0238)

A flaw was discovered in OpenOffice.org’s link handling code. If a user
were tricked into clicking a link in a specially crafted document, a
remote attacker could execute arbitrary shell commands with user
privileges. (CVE-2007-0239)

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.55

Percentile

97.7%