Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.64807
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2009:1426
Summary:NOSUMMARY
Description:Description:
The remote host is missing updates announced in
advisory RHSA-2009:1426.

OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet, presentation manager,
formula editor, and a drawing program.

An integer underflow flaw and a boundary error flaw, both possibly leading
to a heap-based buffer overflow, were found in the way OpenOffice.org
parses certain records in Microsoft Word documents. An attacker could
create a specially-crafted Microsoft Word document, which once opened by an
unsuspecting user, could cause OpenOffice.org to crash or, potentially,
execute arbitrary code with the permissions of the user running
OpenOffice.org. (CVE-2009-0200, CVE-2009-0201)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported patches to correct these issues. All
running instances of OpenOffice.org applications must be restarted for
this update to take effect.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2009-1426.html
http://www.redhat.com/security/updates/classification/#important

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-0200
BugTraq ID: 36200
http://www.securityfocus.com/bid/36200
Bugtraq: 20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Integer Underflow (Google Search)
http://www.securityfocus.com/archive/1/506194/100/0/threaded
Debian Security Information: DSA-1880 (Google Search)
http://www.debian.org/security/2009/dsa-1880
http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2010:035
http://www.mandriva.com/security/advisories?name=MDVSA-2010:091
http://www.mandriva.com/security/advisories?name=MDVSA-2010:105
http://development.openoffice.org/releases/3.1.1.html
http://secunia.com/secunia_research/2009-26/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10881
http://secunia.com/advisories/35036
http://secunia.com/advisories/36750
http://secunia.com/advisories/60799
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1
SuSE Security Announcement: SUSE-SR:2009:015 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html
http://www.vupen.com/english/advisories/2009/2490
Common Vulnerability Exposure (CVE) ID: CVE-2009-0201
Bugtraq: 20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Buffer Overflow (Google Search)
http://www.securityfocus.com/archive/1/506195/100/0/threaded
http://secunia.com/secunia_research/2009-27/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10726
http://www.securitytracker.com/id?1022798
CopyrightCopyright (c) 2009 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2021 E-Soft Inc. All rights reserved.