Submitted by KeesCook on Wed, 2007-07-11 09:16
Referenced CVEs:
CVE-2007-0245
Description:
===========================================================
Ubuntu Security Notice USN-482-1 July 10, 2007
openoffice.org, openoffice.org-amd64 vulnerability
CVE-2007-0245
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
openoffice.org-core 2.0.2-2ubuntu12.4
openoffice.org2-base 2.0.2-2ubuntu12.4
Ubuntu 6.10:
openoffice.org-core 2.0.4-0ubuntu6
Ubuntu 7.04:
openoffice.org-core 2.2.0-1ubuntu4
After a standard system upgrade you need to restart OpenOffice, or
reboot your computer, to effect the necessary changes.
Details follow:
John Heasman discovered that OpenOffice did not correctly validate the
sizes of tags in RTF documents. If a user were tricked into opening a
specially crafted document, a remote attacker could execute arbitrary
code with user privileges.


