search technology reviews, news, features, group tests
Popular Searches:   video , dell , dvd
 |  Register
 |  Newsletters  | 
Sitemap  |  RSS
RSS
Tuesday November 24, 2009 1:20 AM AEST
Skip Navigation LinksPC Authority > News > OpenOffice users urged to apply security fixes
OpenOffice users urged to apply security fixes
NEWS

OpenOffice users urged to apply security fixes

by Shaun Nichols  on Nov 3, 2008
Hackers may be using OpenOffice as a way to execute remote code. A couple of new patches have addressed these critical flaws..
A pair of security fixes have been posted for OpenOffice.

Users are being urged to install both updates, which address flaws in the open-source productivity suite that could be used by an attacker to remotely execute code on targeted systems.

Both vulnerabilities affect all versions of OpenOffice prior to the 2.4.2 release. The recently-unveiled OpenOffice 3.0 release is not believed to be at risk from either vulnerability.

The flaws centre on the way OpenOffice handles certain file types. An attacker could use a specially-crafted WMF or EMF file to cause a heap overflow error that would then leave the attacker able to execute malicious code on the targeted system.

No working exploit for either vulnerability is thought to exist in the wild. Credit for the discovery of both flaws was given to an anonymous researcher operating out of Chinese security firm SureRun.

The French Security Incident Response Team (FrSIRT) has rated both flaws as critical, the highest of its four alert levels. Both FrSIRT and the US Computer Emergency Response Team are advising users to update their copies of OpenOffice to remove the vulnerabilities.

Copyright © 2009 v3.co.uk
Email a Friend Email this
Print Page Print this
Tweet This Tweet this
Feedback Send us your tips


Ads by Google

Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Login or register to submit a comment.
 

Top Stories

Telstra confirm 30Mbit national network plan - but don't mention the NBN
Telstra has completed the 100Mbit upgrade to their Melbourne cable network and are next planning to get 30Mbit speeds into the rest of the country; but first they'll need to dispel those endless NBN comparisons
 
Red Hat updates with Fedora 12
Red Hat has released the latest version of its Fedora open source operating system and has added new video, virtualisation and networking support..
 
Picking the perfect home entertainment box: Movie downloads come to the Xbox 360
Unmetered download agreements are next the battleground as games consoles follow the Apple TV's lead to support movie download services.
 


 
Intel
 
 
LogMeIn
 
 
Amazing Dell Coupons now available
 
Discover Apple