*** This bug is a security vulnerability ***

Public security bug reported:

Binary package hint: openoffice.org

CVE-2008-2152 description:

"A security vulnerability in the custom memory allocation function from
OpenOffice.org may lead to heap overflows and allow a remote
unprivileged user who provides a OpenOffice.org document that is opened
by a local user to execute arbitrary commands on the system with the
privileges of the user running OpenOffice.org. [...]

Affected releases
All versions between OpenOffice.org 2.0 and 2.4 inclusive."

http://www.openoffice.org/security/cves/CVE-2008-2152.html

See also:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=714

** Affects: openoffice.org (Ubuntu)
     Importance: Undecided
         Status: New

** Visibility changed to: Public

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-2152

-- 
[CVE-2008-2152] Integer overflow in rtl_allocateMemory() in OpenOffice.org
https://bugs.launchpad.net/bugs/238925
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to