Ubuntu Security Notice (C) 2010-2014 Canonical, Inc. / NASL script (C) 2010-2014 Tenable Network Security, Inc.
The remote Ubuntu host is missing one or more security-related patches.
It was discovered that the XML HMAC signature system did not correctly
check certain lengths. If an attacker sent a truncated HMAC, it could
bypass authentication, leading to potential privilege escalation.
Sebastian Apelt and Frank ReiÃčner discovered that OpenOffice did not
correctly import XPM and GIF images. If a user were tricked into
opening a specially crafted image, an attacker could execute arbitrary
code with user privileges. (CVE-2009-2949, CVE-2009-2950)
Nicolas Joly discovered that OpenOffice did not correctly handle
certain Word documents. If a user were tricked into opening a
specially crafted document, an attacker could execute arbitrary code
with user privileges. (CVE-2009-3301, CVE-2009-3302)
It was discovered that OpenOffice did not correctly handle certain VBA
macros correctly. If a user were tricked into opening a specially
crafted document, an attacker could execute arbitrary macro commands,
bypassing security controls. (CVE-2010-0136).
Update the affected packages.
Risk factor :
High / CVSS Base Score : 9.3
CVSS Temporal Score : 8.1
Public Exploit Available : true
Family: Ubuntu Local Security Checks
Nessus Plugin ID: 44912 ()
Bugtraq ID: 356713821838245
CVE ID: CVE-2009-0217CVE-2009-2949CVE-2009-2950CVE-2009-3301CVE-2009-3302CVE-2010-0136
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.