Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

OpenOffice < 3.3 Multiple Vulnerabilities

High

Synopsis

The remote host has a program that is affected by multiple vulnerabilities.

Description

Versions of OpenOffice earlier than 3.3 are potentially affected by several issues :

- Issues exist relating to PowerPoint document parsing that may lead to arbitrary code execution. (CVE-2010-2935, CVE-2010-2936)

- A directory traversal vulnerability exists in zip / jar package extraction. (CVE-2010-3450)

- Issues exist relating to RTF document processing that may lead to arbitrary code execution. (CVE-2010-3451, CVE-2010-3452)

- Issues exist relating to Word document processing that may lead to arbitrary code execution. (CVE-2010-3453, CVE-2010-3454)

- The OpenOffice.org start script and other shell scripts expand the LD_LIBRARY_PATH in a way that the current directory might be searched for libraries before /lib and /usr/lib. (CVE-2010-3689)

- Issues exist in the third party XPDF library relating to PDf processing that may allow arbitrary code execution. (CVE-2010-3702, CVE-2010-3704)

- OpenOffice.org includes a version of LIBXML2 that is affected by multiple vulnerabilities. (CVE-2010-4008, CVE-2010-4494)

- An issue exists with PNG file processing that may allow arbitrary code execution. (CVE-2010-4253)

- An issue exists with TGA file processing that may allow arbitrary code execution. (CVE-2010-4643)

Solution

Upgrade to OpenOffice version 3.3 or later.