From 4f2d7949f03e1c198bc888f2d05f421d35c57e21 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 9 Oct 2017 18:53:29 +0100 Subject: reinit the tree, so we can have metadata --- metadata/glsa/glsa-200704-12.xml | 81 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 81 insertions(+) create mode 100644 metadata/glsa/glsa-200704-12.xml (limited to 'metadata/glsa/glsa-200704-12.xml') diff --git a/metadata/glsa/glsa-200704-12.xml b/metadata/glsa/glsa-200704-12.xml new file mode 100644 index 000000000000..ef0765161b8e --- /dev/null +++ b/metadata/glsa/glsa-200704-12.xml @@ -0,0 +1,81 @@ + + + + OpenOffice.org: Multiple vulnerabilities + + Multiple vulnerabilities have been discovered in OpenOffice.org, allowing + for remote execution of arbitrary code. + + OpenOffice.org + 2007-04-16 + 2007-04-16: 01 + 170828 + remote + + + 2.1.0-r1 + 2.1.0-r1 + + + 2.2.0 + 2.2.0 + + + +

+ OpenOffice.org is an open source office productivity suite, including + word processing, spreadsheet, presentation, drawing, data charting, + formula editing, and file conversion facilities. +

+
+ +

+ John Heasman of NGSSoftware has discovered a stack-based buffer + overflow in the StarCalc parser and an input validation error when + processing metacharacters in a link. Also OpenOffice.Org includes code + from libwpd making it vulnerable to heap-based overflows when + converting WordPerfect document tables (GLSA 200704-07). +

+
+ +

+ A remote attacker could entice a user to open a specially crafted + document, possibly leading to execution of arbitrary code with the + rights of the user running OpenOffice.org. +

+
+ +

+ There is no known workaround at this time. +

+
+ +

+ All OpenOffice.org users should upgrade to the latest version: +

+ + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-office/openoffice-2.1.0-r1" +

+ All OpenOffice.org binary users should upgrade to the latest version: +

+ + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-office/openoffice-bin-2.2.0" +
+ + CVE-2007-0002 + CVE-2007-0238 + CVE-2007-0239 + GLSA-200704-07 + + + jaervosz + + + p-y + + + p-y + +
-- cgit v1.2.3