Ubuntu 8.04 LTS / 9.10 / 10.04 LTS / 10.10 : openoffice.org vulnerabilities (USN-1056-1)

High Nessus Plugin ID 51858

Synopsis

The remote Ubuntu host is missing one or more security-related patches.

Description

Charlie Miller discovered several heap overflows in PPT processing. If a user or automated system were tricked into opening a specially crafted PPT document, a remote attacker could execute arbitrary code with user privileges. Ubuntu 10.10 was not affected. (CVE-2010-2935, CVE-2010-2936)

Marc Schoenefeld discovered that directory traversal was not correctly handled in XSLT, OXT, JAR, or ZIP files. If a user or automated system were tricked into opening a specially crafted document, a remote attacker overwrite arbitrary files, possibly leading to arbitrary code execution with user privileges. (CVE-2010-3450)

Dan Rosenberg discovered multiple heap overflows in RTF and DOC processing. If a user or automated system were tricked into opening a specially crafted RTF or DOC document, a remote attacker could execute arbitrary code with user privileges. (CVE-2010-3451, CVE-2010-3452, CVE-2010-3453, CVE-2010-3454)

Dmitri Gribenko discovered that OpenOffice.org did not correctly handle LD_LIBRARY_PATH in various tools. If a local attacker tricked a user or automated system into using OpenOffice.org from an attacker-controlled directory, they could execute arbitrary code with user privileges. (CVE-2010-3689)

Marc Schoenefeld discovered that OpenOffice.org did not correctly process PNG images. If a user or automated system were tricked into opening a specially crafted document, a remote attacker could execute arbitrary code with user privileges. (CVE-2010-4253)

It was discovered that OpenOffice.org did not correctly process TGA images. If a user or automated system were tricked into opening a specially crafted document, a remote attacker could execute arbitrary code with user privileges. (CVE-2010-4643).

Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected packages.

See Also

https://usn.ubuntu.com/1056-1/

Plugin Details

Severity: High

ID: 51858

File Name: ubuntu_USN-1056-1.nasl

Version: 1.10

Type: local

Agent: unix

Published: 2011/02/03

Updated: 2019/09/19

Dependencies: 12634

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 9.3

Temporal Score: 7.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:POC/RL:OF/RC:C

Vulnerability Information

CPE: p-cpe:/a:canonical:ubuntu_linux:broffice.org, p-cpe:/a:canonical:ubuntu_linux:cli-uno-bridge, p-cpe:/a:canonical:ubuntu_linux:libmythes-dev, p-cpe:/a:canonical:ubuntu_linux:libuno-cil, p-cpe:/a:canonical:ubuntu_linux:libuno-cli-basetypes1.0-cil, p-cpe:/a:canonical:ubuntu_linux:libuno-cli-cppuhelper1.0-cil, p-cpe:/a:canonical:ubuntu_linux:libuno-cli-oootypes1.0-cil, p-cpe:/a:canonical:ubuntu_linux:libuno-cli-ure1.0-cil, p-cpe:/a:canonical:ubuntu_linux:libuno-cli-uretypes1.0-cil, p-cpe:/a:canonical:ubuntu_linux:mozilla-openoffice.org, p-cpe:/a:canonical:ubuntu_linux:openoffice.org, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-base, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-base-core, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-calc, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-common, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-core, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-dev, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-dev-doc, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-draw, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-dtd-officedocument1.0, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-emailmerge, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-evolution, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-filter-binfilter, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-filter-mobiledev, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-gcj, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-gnome, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-gtk, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-headless, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-impress, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-java-common, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-kde, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-l10n-in, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-l10n-za, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-math, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-mysql-connector, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-officebean, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-ogltrans, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-pdfimport, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-presentation-minimizer, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-presenter-console, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-qa-api-tests, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-qa-tools, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-report-builder, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-report-builder-bin, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-sdbc-postgresql, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-style-andromeda, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-style-crystal, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-style-galaxy, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-style-hicontrast, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-style-human, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-style-industrial, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-style-oxygen, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-style-tango, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-wiki-publisher, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-writer, p-cpe:/a:canonical:ubuntu_linux:python-uno, p-cpe:/a:canonical:ubuntu_linux:ttf-opensymbol, p-cpe:/a:canonical:ubuntu_linux:uno-libs3, p-cpe:/a:canonical:ubuntu_linux:uno-libs3-dbg, p-cpe:/a:canonical:ubuntu_linux:ure, p-cpe:/a:canonical:ubuntu_linux:ure-dbg, cpe:/o:canonical:ubuntu_linux:10.04:-:lts, cpe:/o:canonical:ubuntu_linux:10.10, cpe:/o:canonical:ubuntu_linux:8.04:-:lts, cpe:/o:canonical:ubuntu_linux:9.10

Required KB Items: Host/cpu, Host/Ubuntu, Host/Ubuntu/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2011/02/02

Vulnerability Publication Date: 2010/08/25

Reference Information

CVE: CVE-2010-2935, CVE-2010-2936, CVE-2010-3450, CVE-2010-3451, CVE-2010-3452, CVE-2010-3453, CVE-2010-3454, CVE-2010-3689, CVE-2010-4253, CVE-2010-4643

BID: 42202, 46031

USN: 1056-1