DSA-2520-1 openoffice.org -- Multiple heap-based buffer overflows

Related Vulnerabilities: CVE-2012-2665  

Timo Warns from PRE-CERT discovered multiple heap-based buffer overflows in OpenOffice.org, an office productivity suite. The issues lies in the XML manifest encryption tag parsing code. Using specially crafted files, an attacker can cause application crash and could cause arbitrary code execution. For the stable distribution (squeeze), this problem has been fixed in version 1:3.2.1-11+squeeze7. openoffice.org package has been replaced by libreoffice in testing (wheezy) and unstable (sid) distributions. For the testing distribution (wheezy), this problem has been fixed in version 1:3.5.4-7. For the unstable distribution (sid), this problem has been fixed in version 1:3.5.4-7. We recommend that you upgrade your openoffice.org packages.

Debian Security Advisory

DSA-2520-1 openoffice.org -- Multiple heap-based buffer overflows

Date Reported:
01 Aug 2012
Affected Packages:
openoffice.org
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2012-2665.
More information:

Timo Warns from PRE-CERT discovered multiple heap-based buffer overflows in OpenOffice.org, an office productivity suite. The issues lies in the XML manifest encryption tag parsing code. Using specially crafted files, an attacker can cause application crash and could cause arbitrary code execution.

For the stable distribution (squeeze), this problem has been fixed in version 1:3.2.1-11+squeeze7.

openoffice.org package has been replaced by libreoffice in testing (wheezy) and unstable (sid) distributions.

For the testing distribution (wheezy), this problem has been fixed in version 1:3.5.4-7.

For the unstable distribution (sid), this problem has been fixed in version 1:3.5.4-7.

We recommend that you upgrade your openoffice.org packages.