From 4f2d7949f03e1c198bc888f2d05f421d35c57e21 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 9 Oct 2017 18:53:29 +0100 Subject: reinit the tree, so we can have metadata --- metadata/glsa/glsa-200504-13.xml | 99 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 99 insertions(+) create mode 100644 metadata/glsa/glsa-200504-13.xml (limited to 'metadata/glsa/glsa-200504-13.xml') diff --git a/metadata/glsa/glsa-200504-13.xml b/metadata/glsa/glsa-200504-13.xml new file mode 100644 index 000000000000..f27573498fb4 --- /dev/null +++ b/metadata/glsa/glsa-200504-13.xml @@ -0,0 +1,99 @@ + + + + OpenOffice.Org: DOC document Heap Overflow + + OpenOffice.Org is vulnerable to a heap overflow when processing DOC + documents, which could lead to arbitrary code execution. + + OpenOffice + 2005-04-15 + 2005-05-08: 02 + 88863 + remote + + + 1.1.4-r1 + 1.1.4-r1 + + + 1.1.4-r1 + 1.1.4-r1 + + + 1.3.9-r1 + 1.3.6-r1 + 1.3.7-r1 + 1.3.9-r1 + + + +

+ OpenOffice.org is an office productivity suite, including word + processing, spreadsheets, presentations, drawings, data charting, + formula editing, and file conversion facilities. +

+
+ +

+ AD-LAB has discovered a heap overflow in the "StgCompObjStream::Load()" + function when processing DOC documents. +

+
+ +

+ An attacker could design a malicious DOC document containing a + specially crafted header which, when processed by OpenOffice.Org, would + result in the execution of arbitrary code with the rights of the user + running the application. +

+
+ +

+ There is no known workaround at this time. +

+
+ +

+ All OpenOffice.Org users should upgrade to the latest version: +

+ + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-office/openoffice-1.1.4-r1" +

+ All OpenOffice.Org binary users should upgrade to the latest version: +

+ + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-office/openoffice-bin-1.1.4-r1" +

+ All OpenOffice.Org Ximian users should upgrade to the latest version: +

+ + # emerge --sync + # emerge --ask --oneshot --verbose app-office/openoffice-ximian +

+ Note to PPC users: There is no stable OpenOffice.Org fixed version for + the PPC architecture. Affected users should switch to the latest + OpenOffice.Org Ximian version. +

+

+ Note to SPARC users: There is no stable OpenOffice.Org fixed version + for the SPARC architecture. Affected users should switch to the latest + OpenOffice.Org Ximian version. +

+
+ + OpenOffice.Org Issue 46388 + CAN-2005-0941 + + + koon + + + formula7 + + + koon + +
-- cgit v1.2.3