NASLDB: Scientific Linux Security Update : openoffice.org on SL5.x i386/x86_64
General
ID: 61410
Name: Scientific Linux Security Update : openoffice.org on SL5.x i386/x86_64
Summary: Checks rpm output for the updated packages
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS Temporal Vector: –
Port: 0
Family: Scientific Linux Local Security Checks
Type: Local
Description
OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet application,
presentation manager, formula editor, and a drawing program.
Multiple heap-based buffer overflow flaws were found in the way
OpenOffice.org processed encryption information in the manifest files
of OpenDocument Format files. An attacker could provide a
specially-crafted OpenDocument Format file that, when opened in an
OpenOffice.org application, would cause the application to crash or,
potentially, execute arbitrary code with the privileges of the user
running the application. (CVE-2012-2665)
All OpenOffice.org users are advised to upgrade to these updated
packages, which contain backported patches to correct these issues.
All running instances of OpenOffice.org applications must be restarted
for this update to take effect.
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2012-2665
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: 2012/08/01
Plugin Release: 2012/08/03
Plugin
Version: 1.2
Filename: sl_20120801_openoffice_org_on_SL5_x.nasl
Filesize: 11066 bytes
MD5 Hash: 99e2c8bca658d513c0770bdc1e9caaa0
Identification: Host/local_checks_enabled
Require Keys: Host/local_checks_enabled", "Host/cpu", "Host/RedHat/release", "Host/RedHat/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2012 Tenable Network Security, Inc.
- Letzte Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













