A patch has been widely released for a vulnerability in the OpenOffice.org productivity suite, a problem rated as "highly critical" by one security vendor. The flaw could be exploited by creating a malicious file in the Windows Metafile (WMF) or Enhanced Metafile (EMF) formats. If the file was opened by a user, it could start running unauthorized code on a computer, according to an advisory by Linux distribution vendor Red Hat, which offers the OpenOffice.org suite with several of its products.

OpenOffice.org is a free software suite that includes a word processor, spreadsheet and a presentation program. It's a competitor to Microsoft Corp.'s Office suite, although it's not as widely used. OpenOffice.org has published a patch, which in turn is being distributed by Red Hat.

View: The full story
News source: PCWorld



There are 4 additional comments
Advertisement
(1 reply) Quote this comment Reply to this comment #1 Posted by Croquant on 05 Jan 2007 - 17:26
So, where's the patch? I don't see anything about this on the OpenOffice.org website.
Quote this comment #1.1 Posted by vetmarkjensen on 05 Jan 2007 - 17:35
I did a bit of digging.

This bug affects OO.o versions 2.0.4 and earlier.

So I guess the "patch" would be to update to current 2.1 (or hunt for the manual patch file on OO.o's website).
Quote this comment Reply to this comment #2 Posted by spook_man on 05 Jan 2007 - 17:31
Most of the distros have the patches out already via their updates..

But found this on OOO's website..

http://www.openoffice.org/servlets/ReadMsg...amp;msgNo=10454
Quote this comment Reply to this comment #3 Posted by RealFduch on 06 Jan 2007 - 10:06
Hmmm...
And people were saying that the WMF vulnerability was backdoor from MS.... So this one is OpenBackdoo­®.Org
[1]

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.


Scroll to the Top
....
My Preferences
....
Communicating with server
Loading
Please Wait...
....
Loading
 X 
....