All Threats

Viruses

Hackers

Spam

Whole site    Viruses
  
About Hackers
Analysis
News
Glossary
Weblog



 
Virus Encyclopedia
Virus Encyclopedia

Learn about worms, viruses, Trojans and more in our Virus Encyclopedia.

About Spam
About Spam

Read about spam and spammers in our About Spam section.

 

  Home / Hackers / About Hackers / Software Vulnerabilities / Examples and Descriptions / SA32419

OpenOffice Multiple Vulnerabilties and Security Issue

Secunia ID

SA32419

CVE-ID

CVE-2008-2237, CVE-2008-2238, CVE-2008-4937

Release Date

29 Oct 2008

Last Change

11 Nov 2008

Criticality

Highly Critical

Solution Status

Vendor Patch

Software

OpenOffice.org 2.x

Where

From remote

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.


Privilege escalation

This covers vulnerabilities where a user is able to conduct certain tasks with the privileges of other users or administrative users.

This typically includes cases where a local user on a client or server system can gain access to the administrator or root account thus taking full control of the system.


Description

Some vulnerabilities and a security issue have been reported in OpenOffice, which potentially can be exploited by malicious people to compromise a user's system, and by malicious, local users to perform certain actions with escalated privileges.

1) An error in the processing of WMF files can be exploited to cause a heap-based buffer overflow via a specially crafted StarOffice/StarSuite document.

2) Multiple integer overflows when parsing certain EMR records of EMF files can be exploited to cause heap-based buffer overflows via a specially crafted StarOffice/StarSuite document.

Successful exploitation of the vulnerabilities may allow execution of arbitrary code.

3) The "senddoc" script uses temporary files in an insecure manner. This can be exploited via symlink attacks to overwrite arbitrary files with the privileges of the user running the affected script.

NOTE: The security issue only affects Unix versions of OpenOffice.

The vulnerabilities are reported in 2.x versions prior to 2.4.2.

Solution

Update to version 2.4.2.

Reported by

1) The vendor credits an anonymous researcher working with the SureRun Security Team
2) Sebastian Apelt and Code Audit Labs, reported via iDefense Labs
3) Reported by Dmitry E. Oboukhov in a Debian bug report.

Original Advisory

OpenOffice.org:
http://www.openoffice.org/security/cves/CVE-2008-2237.html
http://www.openoffice.org/security/cves/CVE-2008-2238.html

iDefense Labs:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=750

Debian:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496361




 

Copyright © 1996 - 2010
Kaspersky Lab
Industry-leading Antivirus Software
All rights reserved
 

Email: webmaster@viruslist.com