Description: | Description:
The remote host is missing an update to openoffice.org announced via advisory FEDORA-2008-9313.
Update Information:
Security update to address - CVE-2008-2237: Manipulated WMF files - CVE-2008-2238: Manipulated EMF files as described at http://www.openoffice.org/security/bulletin.html
ChangeLog:
* Wed Oct 29 2008 Caolan McNamara - 1:2.4.2-18.1 - Resolves: ooo#94495 Toggle weblayout/normal layout and notes - Resolves: rhbz#465792 openoffice.org-2.4.1.ooo81576.vcl.fixscale.patch - Resolves: rhbz#468336 openoffice.org-3.0.0.ooo95533.sw.safertableexport.patch - CVE-2008-2237: Manipulated WMF files - CVE-2008-2238: Manipulated EMF files * Tue Aug 26 2008 Caolan McNamara - 1:2.4.1-17.6 - Resolves: CVE-2008-3282 numeric truncation error in OOo memory allocator - add openoffice.org-2.4.0.ooo93119.shell.echos.patch
References:
[ 1 ] Bug #462639 - CVE-2008-2237 OpenOffice.org WMF integer overflow https://bugzilla.redhat.com/show_bug.cgi?id=462639 [ 2 ] Bug #466528 - CVE-2008-2238 OpenOffice.org multiple EMF buffer overflows https://bugzilla.redhat.com/show_bug.cgi?id=466528
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update openoffice.org' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-9313
Risk factor : Critical
CVSS Score: 9.3
|