RHSA-2010:0101: Important: openoffice.org security update
OpenOffice.org is an office productivity suite that includes desktopapplications, such as a word processor, spreadsheet application,presentation manager, formula editor, and a drawing program.An integer overflow flaw, leading to a heap-based buffer overflow, wasfound in the way OpenOffice.org parsed XPM files. An attacker could createa specially-crafted document, which once opened by a local, unsuspectinguser, could lead to arbitrary code execution with the permissions of theuser running OpenOffice.org. Note: This flaw affects embedded XPM files inOpenOffice.org documents as well as stand-alone XPM files. (CVE-2009-2949)An integer underflow flaw and a boundary error flaw, both possibly leadingto a heap-based buffer overflow, were found in the way OpenOffice.orgparsed certain records in Microsoft Word documents. An attacker couldcreate a specially-crafted Microsoft Word document, which once opened by alocal, unsuspecting user, could cause OpenOffice.org to crash or,potentially, execute arbitrary code with the permissions of the userrunning OpenOffice.org. (CVE-2009-3301, CVE-2009-3302)A heap-based buffer overflow flaw, leading to memory corruption, was foundin the way OpenOffice.org parsed GIF files. An attacker could create aspecially-crafted document, which once opened by a local, unsuspectinguser, could cause OpenOffice.org to crash. Note: This flaw affects embeddedGIF files in OpenOffice.org documents as well as stand-alone GIF files.(CVE-2009-2950)All users of OpenOffice.org are advised to upgrade to these updatedpackages, which contain backported patches to correct these issues. Allrunning instances of OpenOffice.org applications must be restarted for thisupdate to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0101?
The severity of RHSA-2010:0101 is classified as critical due to the potential for remote code execution.
How do I fix RHSA-2010:0101?
To fix RHSA-2010:0101, update the affected OpenOffice.org packages to version 2.3.0-6.11.el5_4.4 or later.
What vulnerability does RHSA-2010:0101 address?
RHSA-2010:0101 addresses an integer overflow flaw that can lead to a heap-based buffer overflow in OpenOffice.org.
Which software is affected by RHSA-2010:0101?
RHSA-2010:0101 affects multiple OpenOffice.org packages including core, calc, writer, and others.
Where can I find more information about RHSA-2010:0101?
More information about RHSA-2010:0101 can usually be found in Red Hat's security advisories or the bug tracking system.