OpenOffice Database Document Processing Unspecified Code Execution

ERCOLINO

Membro dello Staff
Amministratore
Registrato
3 Marzo 2003
Messaggi
252.722
Località
Torino
Secunia Advisory: SA27928
Release Date: 2007-12-05

Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

Software: OpenOffice.org 2.x

CVE reference: CVE-2007-4575 (Secunia mirror)

Want to know the next time vulnerabilities are fixed in this product?
- Companies can be alerted via email and SMS!


Description:
A vulnerability has been reported in OpenOffice, which potentially can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an unspecified error in the HSQLDB database engine and can be exploited to execute arbitrary static Java code via a specially crafted database document.

The vulnerability is reported in versions prior to version 2.3.1.

Solution:
Update to version 2.3.1 (HSQLDB 1.8.0.9).

http://download.openoffice.org/index.html


Bollettino Secunia
 
Indietro
Alto Basso