CVE-2011-2177: High severity apache openoffice vulnerability
A new security flaw, potentially allowing execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools has been reported by the InteVyDis security researchers team: [1] http://intevydis.com/oo0day.html [2] http://twitter.com/#!/legerov/status/75482755194032128
Note: Since no further detailed information is currently available about this flaw, Red Hat Security Response Team is actively investigating the progress done on this (at upstream and reporter side) and will update this record with further information as soon as it is available.
Mitigation: Do not OpenOffice.org documents from untrusted sources.
Other sources
OpenOffice.org v3.3 allows execution of arbitrary code with the privileges of the user running the OpenOffice.org suite tools.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2177?
CVE-2011-2177 has been classified as a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2011-2177?
To remediate CVE-2011-2177, update to a patched version of Apache OpenOffice beyond 3.3.0.
What are the consequences of exploiting CVE-2011-2177?
Exploitation of CVE-2011-2177 could allow attackers to execute arbitrary code with the privileges of the user running the OpenOffice suite.
Which software versions are affected by CVE-2011-2177?
CVE-2011-2177 specifically affects Apache OpenOffice version 3.3.0.
Is there a workaround for CVE-2011-2177?
There are no official workarounds for CVE-2011-2177; thus, updating the software is the recommended approach.