Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.58323
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 1270-1 (openoffice.org)
Summary:The remote host is missing an update to openoffice.org announced via advisory DSA 1270-1. Several security related problems have been discovered in OpenOffice.org, the free office suite. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-0002 iDefense reported several integer overflow bugs in libwpd, a library for handling WordPerfect documents that is included in OpenOffice.org. Attackers are able to exploit these with carefully crafted WordPerfect files that could cause an application linked with libwpd to crash or possibly execute arbitrary code. CVE-2007-0238 Next Generation Security discovered that the StarCalc parser in OpenOffice.org contains an easily exploitable stack overflow that could be used exploited by a specially crafted document to execute arbitrary code. CVE-2007-0239 It has been reported that OpenOffice.org does not escape shell meta characters and is hence vulnerable to execute arbitrary shell commands via a specially crafted document after the user clicked to a prepared link.;; This VT has been deprecated and merged into the VT 'Debian: Security Advisory (DSA-1270)' (OID: 1.3.6.1.4.1.25623.1.0.58326).
Description:Summary:
The remote host is missing an update to openoffice.org announced via advisory DSA 1270-1. Several security related problems have been discovered in OpenOffice.org, the free office suite. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-0002 iDefense reported several integer overflow bugs in libwpd, a library for handling WordPerfect documents that is included in OpenOffice.org. Attackers are able to exploit these with carefully crafted WordPerfect files that could cause an application linked with libwpd to crash or possibly execute arbitrary code. CVE-2007-0238 Next Generation Security discovered that the StarCalc parser in OpenOffice.org contains an easily exploitable stack overflow that could be used exploited by a specially crafted document to execute arbitrary code. CVE-2007-0239 It has been reported that OpenOffice.org does not escape shell meta characters and is hence vulnerable to execute arbitrary shell commands via a specially crafted document after the user clicked to a prepared link.

This VT has been deprecated and merged into the VT 'Debian: Security Advisory (DSA-1270)' (OID: 1.3.6.1.4.1.25623.1.0.58326).

Solution:
For the stable distribution (sarge) these problems have been fixed in
version 1.1.3-9sarge6.

For the testing distribution (etch) these problems have been fixed in
version 2.0.4.dfsg.2-6.

For the unstable distribution (sid) these problems have been fixed in
version 2.0.4.dfsg.2-6.

We recommend that you upgrade your OpenOffice.org packages.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-0002
BugTraq ID: 23006
http://www.securityfocus.com/bid/23006
Bugtraq: 20070316 rPSA-2007-0057-1 libwpd (Google Search)
http://www.securityfocus.com/archive/1/463033/100/0/threaded
Debian Security Information: DSA-1268 (Google Search)
http://www.debian.org/security/2007/dsa-1268
Debian Security Information: DSA-1270 (Google Search)
http://www.debian.org/security/2007/dsa-1270
http://fedoranews.org/cms/node/2805
http://security.gentoo.org/glsa/glsa-200704-07.xml
http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=490
http://www.mandriva.com/security/advisories?name=MDKSA-2007:063
http://www.mandriva.com/security/advisories?name=MDKSA-2007:064
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11535
http://www.redhat.com/support/errata/RHSA-2007-0055.html
http://www.securitytracker.com/id?1017789
http://secunia.com/advisories/24465
http://secunia.com/advisories/24507
http://secunia.com/advisories/24557
http://secunia.com/advisories/24572
http://secunia.com/advisories/24573
http://secunia.com/advisories/24580
http://secunia.com/advisories/24581
http://secunia.com/advisories/24588
http://secunia.com/advisories/24591
http://secunia.com/advisories/24593
http://secunia.com/advisories/24613
http://secunia.com/advisories/24794
http://secunia.com/advisories/24856
http://secunia.com/advisories/24906
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.399659
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102863-1
SuSE Security Announcement: SUSE-SA:2007:023 (Google Search)
http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html
http://www.ubuntu.com/usn/usn-437-1
http://www.vupen.com/english/advisories/2007/0976
http://www.vupen.com/english/advisories/2007/1032
http://www.vupen.com/english/advisories/2007/1339
Common Vulnerability Exposure (CVE) ID: CVE-2007-0238
BugTraq ID: 23067
http://www.securityfocus.com/bid/23067
Bugtraq: 20070404 High Risk Vulnerability in OpenOffice (Google Search)
http://www.securityfocus.com/archive/1/464724/100/0/threaded
http://www.mandriva.com/security/advisories?name=MDKSA-2007:073
http://www.ngssoftware.com/advisories/high-risk-vulnerabilities-in-the-openoffice-suite/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8968
http://www.redhat.com/support/errata/RHSA-2007-0033.html
http://www.redhat.com/support/errata/RHSA-2007-0069.html
http://www.securitytracker.com/id?1017799
http://secunia.com/advisories/24550
http://secunia.com/advisories/24646
http://secunia.com/advisories/24647
http://secunia.com/advisories/24676
http://secunia.com/advisories/24810
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102794-1
http://www.ubuntu.com/usn/usn-444-1
http://www.vupen.com/english/advisories/2007/1117
XForce ISS Database: openoffice-starcalc-bo(33112)
https://exchange.xforce.ibmcloud.com/vulnerabilities/33112
Common Vulnerability Exposure (CVE) ID: CVE-2007-0239
BugTraq ID: 22812
http://www.securityfocus.com/bid/22812
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11422
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102807-1
XForce ISS Database: openoffice-shell-command-execution(33113)
https://exchange.xforce.ibmcloud.com/vulnerabilities/33113
CopyrightCopyright (C) 2008 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.