Ubuntu Security Notice (C) 2008-2013 Canonical, Inc. / NASL script (C) 2009-2013 Tenable Network Security, Inc.
The remote Ubuntu host is missing one or more security-related patches.
USN-677-1 fixed vulnerabilities in OpenOffice.org. The changes
required that openoffice.org-l10n also be updated for the new version
in Ubuntu 8.04 LTS.
Multiple memory overflow flaws were discovered in OpenOffice.org's
handling of WMF and EMF files. If a user were tricked into opening a
specially crafted document, a remote attacker might be able to execute
arbitrary code with user privileges. (CVE-2008-2237, CVE-2008-2238)
Dmitry E. Oboukhov discovered that senddoc, as included in
OpenOffice.org, created temporary files in an insecure way.
Local users could exploit a race condition to create or
overwrite files with the privileges of the user invoking the
program. This issue only affected Ubuntu 8.04 LTS.
Update the affected packages.
Risk factor :
High / CVSS Base Score : 9.3