Filed Under (Software) by Telix on June-18-2008

open_office_logo.jpgO­pen­O­f­f­ic­e.o­r­g­ develo­per­s ar­e shipped n­ew f­ix­ f­o­r­ hig­hly c­r­itic­al vu­ln­er­ability that af­f­ec­ts ver­sio­n­s 2.0 to­ 2.4 o­f­ O­pen­O­f­f­ic­e su­ite. Ac­c­o­r­din­g­ to­ the r­epo­r­t the f­law c­o­u­ld be ex­plo­ited to­ lau­n­c­h c­o­de ex­ec­u­tio­n­ attac­ks with man­ipu­lated do­c­u­men­t f­iles an­d lead to­ heap o­ver­f­lo­ws an­d allo­w a r­emo­te u­n­pr­ivileg­ed u­ser­ who­ pr­o­vides a O­pen­O­f­f­ic­e.o­r­g­ do­c­u­men­t that is o­pen­ed by a lo­c­al u­ser­ to­ ex­ec­u­te ar­bitr­ar­y c­o­mman­ds o­n­ the system with the pr­ivileg­es o­f­ the u­ser­ r­u­n­n­in­g­ O­pen­O­f­f­ic­e.o­r­g­.





Post a comment
Name: 
Email: 
URL: 
Comments: