CVE-2008-3437: Code Injection
OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3437?
CVE-2008-3437 has a moderate severity level due to the potential for arbitrary code execution through malicious updates.
How do I fix CVE-2008-3437?
To fix CVE-2008-3437, upgrade to OpenOffice.org version 2.1.0 or later, which includes proper update verification.
What causes CVE-2008-3437?
CVE-2008-3437 is caused by OpenOffice.org failing to verify the authenticity of updates, allowing man-in-the-middle attacks.
What versions of OpenOffice.org are affected by CVE-2008-3437?
CVE-2008-3437 affects OpenOffice.org versions 1.1.5, 2.0, 2.0.2, 2.0.3, and 2.0.4.
Can CVE-2008-3437 lead to data loss?
Yes, CVE-2008-3437 can lead to data loss or system compromise if a malicious update is successfully executed.