Description: | Description:
The remote host is missing an update to openoffice.org announced via advisory FEDORA-2008-3251.
Update Information:
Following security issues were addressed in this update: # CVE-2007-5745/5747: Manipulated Quattro Pro files can lead to heap overflows and arbitrary code execution # CVE-2007-5746: Manipulated EMF files can lead to heap overflows and arbitrary code execution # CVE-2008-0320: Manipulated OLE files can lead to heap overflows and arbitrary code execution
ChangeLog:
* Thu Apr 17 2008 Caolan McNamara - 1:2.3.0-6.14 - Resolves: rhbz#435688 CVE-2007-5745, CVE-2007-5746, CVE-2007-5747, CVE-2008-0320
References:
[ 1 ] Bug #435678 - CVE-2007-5745 openoffice.org: Quattro Pro files handling heap overflows in Attribute and Font records https://bugzilla.redhat.com/show_bug.cgi?id=435678 [ 2 ] Bug #435675 - CVE-2007-5746 openoffice.org: EMF files parsing EMR_BITBLT record heap overflows https://bugzilla.redhat.com/show_bug.cgi?id=435675 [ 3 ] Bug #435681 - CVE-2007-5747 openoffice.org: Quattro Pro files parsing integer underflow https://bugzilla.redhat.com/show_bug.cgi?id=435681 [ 4 ] Bug #435676 - CVE-2008-0320 openoffice.org: OLE files parsing heap overflows https://bugzilla.redhat.com/show_bug.cgi?id=435676
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update openoffice.org' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-3251
Risk factor : Critical
CVSS Score: 9.3
|