Ubuntu 6.06 LTS / 7.04 / 7.10 : hsqldb, openoffice.org/-amd64 vulnerabilities (USN-609-1)

Ubuntu Security Notice (C) 2008-2015 Canonical, Inc. / NASL script (C) 2008-2015 Tenable Network Security, Inc.

Synopsis :

The remote Ubuntu host is missing one or more security-related patches.

Description :

It was discovered that arbitrary Java methods were not filtered out
when opening databases in OpenOffice.org. If a user were tricked into
running a specially crafted query, a remote attacker could execute
arbitrary Java with user privileges. (CVE-2007-4575)

Multiple memory overflow flaws were discovered in OpenOffice.org's
handling of Quattro Pro, EMF, and OLE files. If a user were tricked
into opening a specially crafted document, a remote attacker might be
able to execute arbitrary code with user privileges. (CVE-2007-5745,
CVE-2007-5746, CVE-2007-5747, CVE-2008-0320).

Solution :

Update the affected packages.

Risk factor :

High / CVSS Base Score : 9.3
CVSS Temporal Score : 7.7
Public Exploit Available : true

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 32189 ()

Bugtraq ID: 26703

CVE ID: CVE-2007-4575