23 Feb 2010
OpenOffice.org has issued a security update addressing six vulnerabilities, four of which could be exploited for arbitrary code execution. The other two could be used to bypass authentication protection.
The company said that the two authorisation flaws lie in the libxml2 and libxmlsec components, and leave the two libraries unable properly to examine and authorise file signatures.
The four remote code execution flaws include vulnerabilities in the handling of XPM and GIF files. OpenOffice.org warned that attackers could target vulnerable systems by embedding the attack files within Open Document Format files.
Another remote code flaw lies in the component used to load Microsoft Word files within OpenOffice.org. The organisation said that attackers could target the flaw with specially crafted Word documents.
The update also fixes a remote code execution vulnerability in the MSVC Runtime component bundled with the suite. OpenOffice.org is not vulnerable to this attack, but the component could be targeted through other applications.
Latest stories from Open Source
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Sneak peek at the forthcoming glass-based machine
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
1329899014.71117-2574 testjobpleaseignore (autoupload...
Embedded C, Linux , RTOS, Agile, MISRA – Embedded...
Software Engineer / Web Developer - Java, JavaScript...
C# , Oracle , Winforms, Junior Software Engineer – Central...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Nearly two weeks late
The OpenOffice.org patches were released on Feb 11. Really rather old news at this point.
Posted by: Michele 24 Feb 2010