Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2007:0033

The remote host is missing updates announced in
advisory RHSA-2007:0033. is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

iDefense reported an integer overflow flaw in libwpd, a library used
internally to for handling Word Perfect documents. An
attacker could create a carefully crafted Word Perfect file that could
cause to crash or possibly execute arbitrary code if the
file was opened by a victim. (CVE-2007-1466)

John Heasman discovered a stack overflow in the StarCalc parser in An attacker could create a carefully crafted StarCalc file
that could cause to crash or possibly execute arbitrary code
if the file was opened by a victim. (CVE-2007-0238)

Flaws were discovered in the way handled hyperlinks. An
attacker could create an document which could run commands
if a victim opened the file and clicked on a malicious hyperlink.

All users of are advised to upgrade to these updated
packages, which contain backported fixes for these issues.

Red Hat would like to thank Fridrich Å trba for alerting us to the issue
CVE-2007-1466 and providing a patch, and John Heasman for

Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

Risk factor : Critical

CVSS Score:

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-0238
BugTraq ID: 23067
Bugtraq: 20070404 High Risk Vulnerability in OpenOffice (Google Search)
Debian Security Information: DSA-1270 (Google Search)
SuSE Security Announcement: SUSE-SA:2007:023 (Google Search)
XForce ISS Database: openoffice-starcalc-bo(33112)
Common Vulnerability Exposure (CVE) ID: CVE-2007-0239
BugTraq ID: 22812
XForce ISS Database: openoffice-shell-command-execution(33113)
Common Vulnerability Exposure (CVE) ID: CVE-2007-1466
BugTraq ID: 23006
Bugtraq: 20070316 rPSA-2007-0057-1 libwpd (Google Search)
Debian Security Information: DSA-1268 (Google Search)
CopyrightCopyright (c) 2007 E-Soft Inc.

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2021 E-Soft Inc. All rights reserved.