Home→Descriptions→SA30599
| Secunia ID | |
| CVE-ID | |
| Release Date |
10 Jun 2008 |
| Last Change |
11 Jun 2008 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
OpenOffice.org 2.x |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
A vulnerability has been reported in OpenOffice, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an integer overflow error in "rtl_allocateMemory()" and can be exploited to cause heap-based buffer overflows via a specially crafted document. Successful exploitation may allow execution of arbitrary code. The vulnerability is reported in versions 2.0 to 2.4. |
| Solution |
Update to version 2.4.1. |
| Reported by |
Sean Larsson, iDefense Labs |
| Original Advisory |
OpenOffice: iDefense: |