REDHAT-BUG-640241: High severity OpenOffice OpenOffice.org vulnerability
An integer signedness error, leading to heap-based buffer out-ouf-bounds read was found in the way OpenOffice.org processed certain Rich Text Format (RTF) tags. If a user opened a specially-crafted RTF file in OpenOffice.org suite tool (oowriter), it could lead to denial of service (oowriter executable crash), or possibly, execute arbitrary code with the privileges of the user running OpenOffice.org Writer.
References: [1] http://www.cs.brown.edu/people/drosenbe/research.html
Acknowledgements:
Red Hat would like to thank OpenOffice.org for reporting this issue. Upstream acknowledges Dan Rosenberg of Virtual Security Research as the original reporter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-640241?
The severity of REDHAT-BUG-640241 is rated as high due to the potential for denial of service.
How do I fix REDHAT-BUG-640241?
To fix REDHAT-BUG-640241, update OpenOffice.org to the latest version provided by the vendor.
What type of vulnerability is REDHAT-BUG-640241?
REDHAT-BUG-640241 is an integer signedness error that leads to a heap-based buffer out-of-bounds read.
What impact does REDHAT-BUG-640241 have on users?
The impact of REDHAT-BUG-640241 on users is primarily denial of service when opening specially crafted RTF files.
Which software is affected by REDHAT-BUG-640241?
The affected software for REDHAT-BUG-640241 is OpenOffice.org.