Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.870624
Category:Red Hat Local Security Checks
Title:RedHat Update for openoffice.org RHSA-2011:0183-01
Summary:The remote host is missing an update for the 'openoffice.org'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'openoffice.org'
package(s) announced via the referenced advisory.

Vulnerability Insight:
OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet application,
presentation manager, formula editor, and a drawing program.

An array index error and an integer signedness error were found in the way
OpenOffice.org parsed certain Rich Text Format (RTF) files. An attacker
could use these flaws to create a specially-crafted RTF file that, when
opened, would cause OpenOffice.org to crash or, possibly, execute arbitrary
code with the privileges of the user running OpenOffice.org.
(CVE-2010-3451, CVE-2010-3452)

A heap-based buffer overflow flaw and an array index error were found in
the way OpenOffice.org parsed certain Microsoft Office Word documents. An
attacker could use these flaws to create a specially-crafted Microsoft
Office Word document that, when opened, would cause OpenOffice.org to crash
or, possibly, execute arbitrary code with the privileges of the user
running OpenOffice.org. (CVE-2010-3453, CVE-2010-3454)

A heap-based buffer overflow flaw was found in the way OpenOffice.org
parsed certain Microsoft Office PowerPoint files. An attacker could use
this flaw to create a specially-crafted Microsoft Office PowerPoint file
that, when opened, would cause OpenOffice.org to crash or, possibly,
execute arbitrary code with the privileges of the user running
OpenOffice.org. (CVE-2010-4253)

A heap-based buffer overflow flaw was found in the way OpenOffice.org
parsed certain TARGA (Truevision TGA) files. An attacker could use this
flaw to create a specially-crafted TARGA file. If a document containing
this specially-crafted TARGA file was opened, or if a user tried to insert
the file into an existing document, it would cause OpenOffice.org to crash
or, possibly, execute arbitrary code with the privileges of the user
running OpenOffice.org. (CVE-2010-4643)

A directory traversal flaw was found in the way OpenOffice.org handled the
installation of XSLT filter descriptions packaged in Java Archive (JAR)
files, as well as the installation of OpenOffice.org Extension (.oxt)
files. An attacker could use these flaws to create a specially-crafted XSLT
filter description or extension file that, when opened, would cause the
OpenOffice.org Extension Manager to modify files accessible to the user
installing the JAR or extension file. (CVE-2010-3450)

A flaw was found in the script that launches OpenOffice.org. In some
situations, a '.' character could be include ...

Description truncated, please see the referenced URL(s) for more information.

Affected Software/OS:
openoffice.org on Red Hat Enterprise Linux Desktop (v. 6),
Red Hat Enterprise Linux Workstation (v. 6)

Solution:
Please Install the Updated Packages.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-3450
BugTraq ID: 46031
http://www.securityfocus.com/bid/46031
Debian Security Information: DSA-2151 (Google Search)
http://www.debian.org/security/2011/dsa-2151
http://www.gentoo.org/security/en/glsa/glsa-201408-19.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2011:027
http://osvdb.org/70711
http://www.redhat.com/support/errata/RHSA-2011-0181.html
http://www.redhat.com/support/errata/RHSA-2011-0182.html
http://www.securitytracker.com/id?1025002
http://secunia.com/advisories/40775
http://secunia.com/advisories/42999
http://secunia.com/advisories/43065
http://secunia.com/advisories/43105
http://secunia.com/advisories/43118
http://secunia.com/advisories/60799
http://ubuntu.com/usn/usn-1056-1
http://www.vupen.com/english/advisories/2011/0230
http://www.vupen.com/english/advisories/2011/0232
http://www.vupen.com/english/advisories/2011/0279
Common Vulnerability Exposure (CVE) ID: CVE-2010-3451
http://www.cs.brown.edu/people/drosenbe/research.html
http://www.vsecurity.com/resources/advisory/20110126-1
http://osvdb.org/70712
XForce ISS Database: ooo-rtf-ce(65030)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65030
Common Vulnerability Exposure (CVE) ID: CVE-2010-3452
http://osvdb.org/70713
XForce ISS Database: ooo-oowriter-ce(65031)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65031
Common Vulnerability Exposure (CVE) ID: CVE-2010-3453
http://osvdb.org/70714
Common Vulnerability Exposure (CVE) ID: CVE-2010-3454
http://osvdb.org/70715
Common Vulnerability Exposure (CVE) ID: CVE-2010-3689
http://osvdb.org/70716
http://www.securitytracker.com/id?1025004
Common Vulnerability Exposure (CVE) ID: CVE-2010-4253
http://osvdb.org/70717
Common Vulnerability Exposure (CVE) ID: CVE-2010-4643
http://osvdb.org/70718
XForce ISS Database: ooo-tga-bo(65441)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65441
CopyrightCopyright (c) 2012 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2021 E-Soft Inc. All rights reserved.