Security Patch for OpenOffice 19
An anonymous reader writes "Linuxlookup.com is reporting all users of OpenOffice.org 1.1.4 are urged to download and install this security patch. It addresses a problem noted in a recent advisory. That advisory states that there is a security risk in all circulating releases of OpenOffice.org. This patch fixes the problem in 1.1.4 but not in earlier or subsequent releases."
This just goes to show... (Score:3, Funny)
Oh, wait...
not _that_ serious.. (Score:2)
"II.DETAILS:
----------
There is a vulnerability in StgCompObjStream::Load() function,
When reading DOC document information of format,memory is allocated by DOC provide
length.
DOC provided a 32 bits integer,and will use the low 16 bits of this number to allocate
memory,
but when reading doc information,still use the 32 bits number as length,this maybe
cause heap
overflow, and when free happened
excute
No ide
ITS ABOUT TIME (Score:2)
Re:ITS ABOUT TIME (Score:3, Insightful)
Heh. 'Good' is relative to who you like or dislike. If this story was about Office, it would be 'bad' that the problem existed at all.
Re:ITS ABOUT TIME (Score:2)
If this story was about Office, it would be 'bad' that the problem existed at all.
Yes, it would be bad.
But people are entitled to gripe more loudly about MS Office because they have paid more money for it than for OpenOffice.
When a customer discovers a manufacturing defect in the product they bought from MS there isn't a flurry of refunds forthcoming. Instead, dissatisfied customers might get a free downloadable patch in a while, essentially the same level of redress that OpenOffice.org users got for t
Re:ITS ABOUT TIME (Score:2)
Somehow I doubt most of the griping here comes from legitimate Office customers. Afterall, I thought everybody ran Linux here.
Re:ITS ABOUT TIME (Score:2)
No, it was found 3 days ago [securityfocus.com].. Gentoo had the patch and a new ebuild that day.
Re:ITS ABOUT TIME (Score:2)
Awesome, I had the patch before this hit slashdot the first time round.
Re:ITS ABOUT TIME (Score:2)
You didn't. openoffice-bin-1.1.4-r1 also contained the fix. No need to compile at all.
Affects people loading malicious MS Word files. (Score:2)
In portage since the 12th (Score:2)
Re:In portage since the 12th (Score:2)
How about StarOffice? (Score:2)
I'm on the StarOffice 8 beta program ... anyone know if this version is vulnerable on Linux? I assume so, since it's based on an OOo 2.0 beta build.