Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.58354
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1307-1)
Summary:The remote host is missing an update for the Debian 'openoffice.org' package(s) announced via the DSA-1307-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'openoffice.org' package(s) announced via the DSA-1307-1 advisory.

Vulnerability Insight:
John Heasman discovered a heap overflow in the routines of OpenOffice.org that parse RTF files. A specially crafted RTF file could cause the filter to overwrite data on the heap, which may lead to the execution of arbitrary code.

For the old stable distribution (sarge) this problem has been fixed in version 1.1.3-9sarge7.

For the stable distribution (etch) this problem has been fixed in version 2.0.4.dfsg.2-7etch1.

For the unstable distribution (sid) this problem has been fixed in version 2.2.1~
rc1-1.

We recommend that you upgrade your openoffice.org packages.

Affected Software/OS:
'openoffice.org' package(s) on Debian 3.1, Debian 4.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-0245
BugTraq ID: 24450
http://www.securityfocus.com/bid/24450
Bugtraq: 20070613 High risk vulnerability in OpenOffice RTF parser (Google Search)
http://www.securityfocus.com/archive/1/471274/100/0/threaded
Debian Security Information: DSA-1307 (Google Search)
http://www.debian.org/security/2007/dsa-1307
http://www.gentoo.org/security/en/glsa/glsa-200707-02.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2007:144
http://osvdb.org/35378
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10002
http://www.redhat.com/support/errata/RHSA-2007-0406.html
http://www.securitytracker.com/id?1018239
http://secunia.com/advisories/25648
http://secunia.com/advisories/25650
http://secunia.com/advisories/25673
http://secunia.com/advisories/25705
http://secunia.com/advisories/25862
http://secunia.com/advisories/25894
http://secunia.com/advisories/25905
http://secunia.com/advisories/26010
http://secunia.com/advisories/26022
http://secunia.com/advisories/26476
SGI Security Advisory: 20070602-01-P
ftp://patches.sgi.com/support/free/security/advisories/20070602-01-P.asc
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102917-1
SuSE Security Announcement: SUSE-SA:2007:037 (Google Search)
http://www.novell.com/linux/security/advisories/2007_37_openoffice.html
http://www.ubuntu.com/usn/usn-482-1
http://www.vupen.com/english/advisories/2007/2166
http://www.vupen.com/english/advisories/2007/2229
XForce ISS Database: openoffice-rtf-bo(34843)
https://exchange.xforce.ibmcloud.com/vulnerabilities/34843
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.