Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.64807
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2009:1426
Summary:The remote host is missing updates announced in;advisory RHSA-2009:1426.;;OpenOffice.org is an office productivity suite that includes desktop;applications, such as a word processor, spreadsheet, presentation manager,;formula editor, and a drawing program.;;An integer underflow flaw and a boundary error flaw, both possibly leading;to a heap-based buffer overflow, were found in the way OpenOffice.org;parses certain records in Microsoft Word documents. An attacker could;create a specially-crafted Microsoft Word document, which once opened by an;unsuspecting user, could cause OpenOffice.org to crash or, potentially,;execute arbitrary code with the permissions of the user running;OpenOffice.org. (CVE-2009-0200, CVE-2009-0201);;All users of OpenOffice.org are advised to upgrade to these updated;packages, which contain backported patches to correct these issues. All;running instances of OpenOffice.org applications must be restarted for;this update to take effect.
Description:Summary:
The remote host is missing updates announced in
advisory RHSA-2009:1426.

OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet, presentation manager,
formula editor, and a drawing program.

An integer underflow flaw and a boundary error flaw, both possibly leading
to a heap-based buffer overflow, were found in the way OpenOffice.org
parses certain records in Microsoft Word documents. An attacker could
create a specially-crafted Microsoft Word document, which once opened by an
unsuspecting user, could cause OpenOffice.org to crash or, potentially,
execute arbitrary code with the permissions of the user running
OpenOffice.org. (CVE-2009-0200, CVE-2009-0201)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported patches to correct these issues. All
running instances of OpenOffice.org applications must be restarted for
this update to take effect.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-0200
BugTraq ID: 36200
http://www.securityfocus.com/bid/36200
Bugtraq: 20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Integer Underflow (Google Search)
http://www.securityfocus.com/archive/1/506194/100/0/threaded
Debian Security Information: DSA-1880 (Google Search)
http://www.debian.org/security/2009/dsa-1880
http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2010:035
http://www.mandriva.com/security/advisories?name=MDVSA-2010:091
http://www.mandriva.com/security/advisories?name=MDVSA-2010:105
http://development.openoffice.org/releases/3.1.1.html
http://secunia.com/secunia_research/2009-26/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10881
http://secunia.com/advisories/35036
http://secunia.com/advisories/36750
http://secunia.com/advisories/60799
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1
SuSE Security Announcement: SUSE-SR:2009:015 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html
http://www.vupen.com/english/advisories/2009/2490
Common Vulnerability Exposure (CVE) ID: CVE-2009-0201
Bugtraq: 20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Buffer Overflow (Google Search)
http://www.securityfocus.com/archive/1/506195/100/0/threaded
http://secunia.com/secunia_research/2009-27/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10726
http://www.securitytracker.com/id?1022798
CopyrightCopyright (C) 2009 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.