Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.57059
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2006:0573
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory RHSA-2006:0573.

OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

A Sun security specialist reported an issue with the application framework.
An attacker could put macros into document locations that could cause
OpenOffice.org to execute them when the file was opened by a victim.
(CVE-2006-2198)

A bug was found in the OpenOffice.org Java virtual machine implementation.
An attacker could write a carefully crafted Java applet that can break
through the sandbox and have full access to system resources with the
current user privileges. (CVE-2006-2199)

A buffer overflow bug was found in the OpenOffice.org file processor. An
attacker could create a carefully crafted XML file that could cause
OpenOffice.org to write data to an arbitrary location in memory when the
file was opened by a victim. (CVE-2006-3117)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported fixes for these issues.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2006-0573.html
http://www.openoffice.org/security/bulletin-20060629.html
http://www.redhat.com/security/updates/classification/#important

Risk factor : High

CVSS Score:
7.6

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-2198
BugTraq ID: 18738
http://www.securityfocus.com/bid/18738
Bugtraq: 20060926 rPSA-2006-0173-1 openoffice.org (Google Search)
http://www.securityfocus.com/archive/1/447035/100/0/threaded
CERT/CC vulnerability note: VU#170113
http://www.kb.cert.org/vuls/id/170113
Debian Security Information: DSA-1104 (Google Search)
http://www.debian.org/security/2006/dsa-1104
http://fedoranews.org/cms/node/2343
http://security.gentoo.org/glsa/glsa-200607-12.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:118
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11082
http://www.redhat.com/support/errata/RHSA-2006-0573.html
http://securitytracker.com/id?1016414
http://secunia.com/advisories/20867
http://secunia.com/advisories/20893
http://secunia.com/advisories/20910
http://secunia.com/advisories/20911
http://secunia.com/advisories/20913
http://secunia.com/advisories/20975
http://secunia.com/advisories/20995
http://secunia.com/advisories/21278
http://secunia.com/advisories/22129
http://secunia.com/advisories/23620
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102490-1
SuSE Security Announcement: SUSE-SA:2006:040 (Google Search)
http://www.novell.com/linux/security/advisories/2006_40_openoffice.html
http://www.ubuntu.com/usn/usn-313-1
http://www.ubuntu.com/usn/usn-313-2
http://www.vupen.com/english/advisories/2006/2607
http://www.vupen.com/english/advisories/2006/2621
XForce ISS Database: openoffice-macro-code-execution(27564)
https://exchange.xforce.ibmcloud.com/vulnerabilities/27564
Common Vulnerability Exposure (CVE) ID: CVE-2006-2199
BugTraq ID: 18737
http://www.securityfocus.com/bid/18737
CERT/CC vulnerability note: VU#243681
http://www.kb.cert.org/vuls/id/243681
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11338
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102475-1
XForce ISS Database: openoffice-applet-sandbox-bypass(27569)
https://exchange.xforce.ibmcloud.com/vulnerabilities/27569
Common Vulnerability Exposure (CVE) ID: CVE-2006-3117
BugTraq ID: 18739
http://www.securityfocus.com/bid/18739
http://www.ngssoftware.com/advisories/openoffice.txt
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9704
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102501-1
XForce ISS Database: openoffice-xml-document-bo(27571)
https://exchange.xforce.ibmcloud.com/vulnerabilities/27571
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2021 E-Soft Inc. All rights reserved.