OpenOffice hit by 'highly critical' flaw

Problems dealing with Tiff images could allow remote access

Matt Chapman

A 'highly critical' flaw has been discovered in the OpenOffice suite of products that could allow hackers to access a user's system.

The vulnerability is caused by integer overflows when processing certain tags within Tiff images.

Advertisement

This problem could be exploited to cause heap-based buffer overflows, possibly by tricking a user into opening a specially crafted document.

Successful exploitation could allow the execution of arbitrary code and compromise a user's system, according to Secunia, which rated the vulnerability as 'highly critical'.

The vulnerabilities are reported in versions earlier than OpenOffice 2.3 and the problem can be fixed by upgrading to the latest version of the software.

Red Hat has updated its OpenOffice packages to correct the security issue in Red Hat Enterprise Linux versions 3, 4 and 5.

OpenOffice is a free office productivity suite that includes a word processor, spreadsheet, presentation manager, formula editor and drawing program.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Microsoft

Windows 2000 flaw highlights slow Patch Tuesday

Vista and XP spared from most dangerous vulnerabilities

Apple iTunes

Apple slips security fix into iTunes update

Software exposes users to remote code execution vulnerability

Security flaw hits MSN Messenger

Vulnerability puts users at risk of arbitrary code execution

Security flaw hits Symantec Enterprise Firewall

Similar issues in Cisco and Checkpoint products, NTA Monitor warns

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

HTC Hero

Hands on with the HTC Hero

V3.co.uk gets a walk through of the Hero, which includes...

NetGear ReadyNAS NVX

Review: NetGear ReadyNAS NVX

NetGear's four-bay compact network-attached storage gets a serious speed boost

AMD

AMD adds to six-core Opteron line up

New HE processors promise even lower power consumption

Adobe Systems

Adobe launches ColdFusion 9 and ColdFusion Builder

Firm promises enhanced developer productivity

Primary Navigation