Lucene search

K
ubuntuUbuntuUSN-677-1
HistoryNov 26, 2008 - 12:00 a.m.

OpenOffice.org vulnerabilities

2008-11-2600:00:00
ubuntu.com
37

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.124 Low

EPSS

Percentile

95.4%

Releases

  • Ubuntu 8.10
  • Ubuntu 8.04
  • Ubuntu 7.10
  • Ubuntu 6.06

Packages

Details

Multiple memory overflow flaws were discovered in OpenOffice.org’s handling of
WMF and EMF files. If a user were tricked into opening a specially crafted
document, a remote attacker might be able to execute arbitrary code with user
privileges. (CVE-2008-2237, CVE-2008-2238)

Dmitry E. Oboukhov discovered that senddoc, as included in OpenOffice.org,
created temporary files in an insecure way. Local users could exploit a race
condition to create or overwrite files with the privileges of the user invoking
the program. This issue only affected Ubuntu 8.04 LTS. (CVE-2008-4937)

OSVersionArchitecturePackageVersionFilename
Ubuntu8.10noarchopenoffice.org-core<Β 1:2.4.1-11ubuntu2.1UNKNOWN
Ubuntu8.10noarchcli-uno-bridge<Β 1:2.4.1-11ubuntu2.1UNKNOWN
Ubuntu8.10noarchlibmythes-dev<Β 1:2.4.1-11ubuntu2.1UNKNOWN
Ubuntu8.10noarchmozilla-openoffice.org<Β 1:2.4.1-11ubuntu2.1UNKNOWN
Ubuntu8.10noarchopenoffice.org<Β 1:2.4.1-11ubuntu2.1UNKNOWN
Ubuntu8.10noarchopenoffice.org<Β base-1:2.4.1-11ubuntu2.1UNKNOWN
Ubuntu8.10noarchopenoffice.org<Β base-core-1:2.4.1-11ubuntu2.1UNKNOWN
Ubuntu8.10noarchopenoffice.org<Β calc-1:2.4.1-11ubuntu2.1UNKNOWN
Ubuntu8.10noarchopenoffice.org<Β core-1:2.4.1-11ubuntu2.1UNKNOWN
Ubuntu8.10noarchopenoffice.org<Β dev-1:2.4.1-11ubuntu2.1UNKNOWN
Rows per page:
1-10 of 921

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.124 Low

EPSS

Percentile

95.4%