Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Ubuntu Local Security Checks >> USN121-1 : openoffice.org vulnerability


Vulnerability Assessment Details

USN121-1 : openoffice.org vulnerability

Vulnerability Assessment Summary
openoffice.org vulnerability

Detailed Explanation for this Vulnerability Assessment

Summary :

These remote packages are missing security patches :
- openoffice.org
- openoffice.org-bin
- openoffice.org-crashrep
- openoffice.org-gtk-gnome
- openoffice.org-kde
- openoffice.org-l10n-af
- openoffice.org-l10n-ar
- openoffice.org-l10n-ca
- openoffice.org-l10n-cs
- openoffice.org-l10n-cy
- openoffice.org-l10n-da
- openoffice.org-l10n-de
- openoffice.org-l10n-el
- openoffice.org-l10n-en
- openoffice.org-l10n-es
- openoffice.org-l10n-et
- openoffice.org-l10n-eu
- openoffice.org-l10n-fi
- o
[...]

Description :

The StgCompObjStream::Load() failed to check the validity of a length
field in documents. If a possible hacker tricked a user to open a specially
crafted OpenOffice file, this triggered a buffer overflow which could
lead to arbitrary code execution with the rights of the user
opening the document.

The update for Ubuntu 5.04 (Hoary Hedgehog) also contains a
translation update: The "openoffice.org-l10n-xh" package now contains
actual Xhosa translations (the previous version just shipped English
strings).

Solution :

Upgrade to :
- openoffice.org-1.1.3-8ubuntu2.3 (Ubuntu 5.04)
- openoffice.org-bin-1.1.3-8ubuntu2.3 (Ubuntu 5.04)
- openoffice.org-crashrep-1.1.2-2ubuntu6.1 (Ubuntu 4.10)
- openoffice.org-gtk-gnome-1.1.3-8ubuntu2.3 (Ubuntu 5.04)
- openoffice.org-kde-1.1.3-8ubuntu2.3 (Ubuntu 5.04)
- openoffice.org-l10n-af-1.1.3-8ubuntu2.3 (Ubuntu 5.04)
- openoffice.org-l10n-ar-1.1.3-8ubuntu2.3 (Ubuntu 5.04)
- openoffice.org-l10n-ca-1.1.3-8ubuntu2.3 (Ubuntu 5.04)
- openoffice.org-l10n-cs-1.1.3-8ubuntu2.3 (Ubuntu 5.04)
- open
[...]


Network Security Threat Level: High


Networks Security ID:

Vulnerability Assessment Copyright: Ubuntu Security Notice (C) 2005 Canonical, Inc. / NASL script (C) 2005 Michel Arboi

Cables, Connectors


Cisco Systems NCS2K-20-SMRFS-L optical multiplexor CISCO EXCESS picture

Cisco Systems NCS2K-20-SMRFS-L optical multiplexor CISCO EXCESS

$3599.00



Cisco SG110 24 Port Gigabit Ethernet Switch w/ 2 x SFP SG110-24 picture

Cisco SG110 24 Port Gigabit Ethernet Switch w/ 2 x SFP SG110-24

$117.00



Cisco WS-C3850-48P-L 48-Port Gigabit 3850 PoE Switch w/ 715W+ C3850-NM-4-1G Mod picture

Cisco WS-C3850-48P-L 48-Port Gigabit 3850 PoE Switch w/ 715W+ C3850-NM-4-1G Mod

$83.00



Cisco C3850-NM-2-10G 2 Port Network Exp.Module for 3850 picture

Cisco C3850-NM-2-10G 2 Port Network Exp.Module for 3850

$38.99



 Lot of 4 Cisco QSFP-40G-SR-BD 10-2945-02 Transceiver Modules  Hologram picture

Lot of 4 Cisco QSFP-40G-SR-BD 10-2945-02 Transceiver Modules Hologram

$47.99



Cisco Catalyst WS-C2960-48TT-L V02 48 Port Fast Ethernet Switch picture

Cisco Catalyst WS-C2960-48TT-L V02 48 Port Fast Ethernet Switch

$34.00



Cisco C9200 48-Port Gigabit Network Switch With Ears P/N: C9200-48T-E Dual Power picture

Cisco C9200 48-Port Gigabit Network Switch With Ears P/N: C9200-48T-E Dual Power

$799.97



New Cisco C9200-NM-4X Catalyst 9200 Series Network Module 4 X 10GE *MINT* picture

New Cisco C9200-NM-4X Catalyst 9200 Series Network Module 4 X 10GE *MINT*

$429.97



Discussions

No Discussions have been posted on this vulnerability.