SCIENTIFIC-LINUX-ERRATA Archives

June 2008

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Troy Dawson <[log in to unmask]>
Reply To:
Troy Dawson <[log in to unmask]>
Date:
Mon, 16 Jun 2008 19:00:39 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (48 lines)
Synopsis:	Important: openoffice.org security update
Issue date:	2008-06-12
CVE Names:	CVE-2008-2152 CVE-2008-2366

Sean Larsson found a heap overflow flaw in the OpenOffice memory 
allocator.  If a carefully crafted file was opened by a victim, an 
attacker could use the flaw to crash OpenOffice.org or, possibly, 
execute arbitrary code. (CVE-2008-2152)

It was discovered that certain libraries in the Scientific Linux 3 and 4 
openoffice.org packages had an insecure relative RPATH (runtime
library search path) set in the ELF (Executable and Linking Format) 
header. A local user able to convince another user to run OpenOffice in 
an attacker-controlled directory, could run arbitrary code with the 
privileges of the victim. (CVE-2008-2366)

SL 3.0.x

     SRPMS:
openoffice.org-1.1.2-42.2.0.EL3.src.rpm
     i386:
openoffice.org-1.1.2-42.2.0.EL3.i386.rpm
openoffice.org-i18n-1.1.2-42.2.0.EL3.i386.rpm
openoffice.org-libs-1.1.2-42.2.0.EL3.i386.rpm
     x86_64:
openoffice.org-1.1.2-42.2.0.EL3.i386.rpm
openoffice.org-i18n-1.1.2-42.2.0.EL3.i386.rpm
openoffice.org-libs-1.1.2-42.2.0.EL3.i386.rpm

SL 4.x

     SRPMS:
openoffice.org-1.1.5-10.6.0.5.EL4.src.rpm
     i386:
openoffice.org-1.1.5-10.6.0.5.EL4.i386.rpm
openoffice.org-i18n-1.1.5-10.6.0.5.EL4.i386.rpm
openoffice.org-kde-1.1.5-10.6.0.5.EL4.i386.rpm
openoffice.org-libs-1.1.5-10.6.0.5.EL4.i386.rpm
     x86_64:
openoffice.org-1.1.5-10.6.0.5.EL4.i386.rpm
openoffice.org-i18n-1.1.5-10.6.0.5.EL4.i386.rpm
openoffice.org-kde-1.1.5-10.6.0.5.EL4.i386.rpm
openoffice.org-libs-1.1.5-10.6.0.5.EL4.i386.rpm


-Connie Sieh
-Troy Dawson

ATOM RSS1 RSS2