First published: Wed Nov 04 2009(Updated: )
An integer underflow flaw, possibly leading to a heap-based buffer overflow, was found in the way OpenOffice.org parsed certain records in Microsoft Word documents. An attacker could create a specially-crafted Microsoft Word document, which once opened by a local, unsuspecting user, could cause OpenOffice.org to crash or, potentially, execute arbitrary code with the permissions of the user running OpenOffice.org. Credit: Nicolas Joly of VUPEN Vulnerability Research Team
Affected Software | Affected Version | How to fix |
---|---|---|
Apache OpenOffice |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-533038 is categorized as critical due to the potential for exploitation through malicious Microsoft Word documents.
To fix REDHAT-BUG-533038, you should update to a patched version of Apache OpenOffice that addresses this vulnerability.
REDHAT-BUG-533038 is an integer underflow flaw that may lead to a heap-based buffer overflow.
Users of Apache OpenOffice who open specially-crafted Microsoft Word documents are affected by REDHAT-BUG-533038.
While an update is the best solution, users can mitigate REDHAT-BUG-533038 by avoiding opening untrusted Microsoft Word documents.