First published: Mon Aug 23 2010(Updated: )
OpenOffice.org is an office productivity suite that includes desktop<br>applications, such as a word processor, spreadsheet application,<br>presentation manager, formula editor, and a drawing program.<br>An integer truncation error, leading to a heap-based buffer overflow, was<br>found in the way the OpenOffice.org Impress presentation application<br>sanitized a file's dictionary property items. An attacker could use this<br>flaw to create a specially-crafted Microsoft Office PowerPoint file that,<br>when opened, would cause OpenOffice.org Impress to crash or, possibly,<br>execute arbitrary code with the privileges of the user running<br>OpenOffice.org Impress. (CVE-2010-2935)<br>An integer overflow flaw, leading to a heap-based buffer overflow, was<br>found in the way OpenOffice.org Impress processed polygons in input<br>documents. An attacker could use this flaw to create a specially-crafted<br>Microsoft Office PowerPoint file that, when opened, would cause<br>OpenOffice.org Impress to crash or, possibly, execute arbitrary code with<br>the privileges of the user running OpenOffice.org Impress. (CVE-2010-2936)<br>All users of OpenOffice.org are advised to upgrade to these updated<br>packages, which contain backported patches to correct these issues. For Red<br>Hat Enterprise Linux 3, this erratum provides updated openoffice.org<br>packages. For Red Hat Enterprise Linux 4, this erratum provides updated<br>openoffice.org and openoffice.org2 packages. All running instances of<br>OpenOffice.org applications must be restarted for this update to take<br>effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/openoffice.org2 | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-base | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-calc | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-core | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-draw | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-emailmerge | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-graphicfilter | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-impress | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-javafilter | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-langpack-ar | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-langpack-bn | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-langpack-de | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-langpack-es | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-langpack-fr | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-langpack-it | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-langpack-ru | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-langpack-sv | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-math | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-pyuno | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-testtools | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-writer | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
redhat/openoffice.org2-xsltfilter | <2.0.4-5.7.0.6.1.el4_8.6 | 2.0.4-5.7.0.6.1.el4_8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.