22 Mar 2007
OpenOffice users have been warned to be vigilant following the disclosure of three vulnerabilities in the popular open source alternative to Microsoft Office.
Security firm Secunia classified the trio of vulnerabilities as 'highly critical', the company's second-highest alert level.
The vulnerabilities could be exploited to cause anything from a denial-of-service attack to remote execution of code.
The first vulnerability lies in the StarCalc spreadsheet component of OpenOffice. An attacker could use a specially-crafted StarCalc file to exploit the vulnerability and remotely execute code on a user's system.
Discovery of the vulnerability has been credited to security firm Next Generation Security Software.
The second vulnerability, first reported by research firm iDefense, lies in the component of OpenOffice that handles WordPerfect (.wpd) files.
If a user can be persuaded to open a specially-crafted .wpd file, an exploit could be triggered to allow an attacker to remotely execute malware, according to an iDefense advisory.
The third vulnerability could allow an attacker to execute arbitrary shell commands within OpenOffice.
Linux developer group Debian said that a user who clicked on a link within a specially-crafted document would be vulnerable to the attack.
Secunia has urged users to avoid opening suspicious OpenOffice files.
Latest stories from Open Source
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Credit Risk Modeller, SAS, London, £50,000 Title- Credit...
My London client is looking for an experienced Programme...
My leading client is looking for a number of excellent...
My client, a leading international name in Manufacturing...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Already fixed
Is this even notable? Honestly, open source security holes are a joke to fix. Not only has this problem been resolved by the time I post this, but that update is already available to everyone everywhere. Nobody should be opening suspicious attachments anyways. It's just "common" sense.
Posted by: Sy Ali 29 Mar 2007