what you don't know can hurt you
Showing 1 - 1 of 1 RSS Feed

Files

Mandriva Linux Security Advisory 2010-091
Posted May 5, 2010
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2010-091 - This update provides a new OpenOffice.org version 3.1.1. An integer underflow might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow. A heap-based buffer overflow might allow remote attackers to execute arbitrary code via unspecified records in a crafted Word document, related to table parsing. A heap-based buffer overflow allows remote attackers to execute arbitrary code via a crafted EMF file. Multiple heap-based buffer overflows allow remote attackers to execute arbitrary code via a crafted EMF+ file. OpenOffice's xmlsec uses a bundled Libtool which might load.la file in the current working directory allowing local users to gain privileges via a Trojan horse file. For enabling such vulnerability xmlsec has to use --enable-crypto_dl building flag however it does not, although the fix keeps protected against this threat whenever that flag had been enabled.

tags | advisory, remote, overflow, arbitrary, local, trojan
systems | linux, mandriva
advisories | CVE-2009-0200, CVE-2009-0201, CVE-2009-2139, CVE-2009-2140, CVE-2009-3736
MD5 | bfbffa42ccc8de8ca867526115f1eca4
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
These Are The 29 Countries Vulnerable To SIM Jacker Attacks
Posted Oct 14, 2019

tags | headline, hacker, phone, cybercrime, fraud, password, identity theft
China's Study The Great Nation App Enables Spying Via Back Door
Posted Oct 14, 2019

tags | headline, government, privacy, phone, china, spyware
Vulnerability Found And Fixed In HP Bloatware
Posted Oct 14, 2019

tags | headline, flaw, patch
Hammond Held In Contempt For Refusing To Answer Questions
Posted Oct 14, 2019

tags | headline, hacker, government, usa, data loss, anonymous, military
Feds Arrest International ATM Skimmer Ring
Posted Oct 11, 2019

tags | headline, government, bank, cybercrime, fraud
Planes, Gate, And Bags: How Hackers Can Hijack Your Local Airport
Posted Oct 11, 2019

tags | headline, hacker, terror
Teenagers Arrested Over Hacks To Met Police Website
Posted Oct 11, 2019

tags | headline, hacker, government, britain
Sophisticated Spy Kit Targets Russians With Rare GSM Plugin
Posted Oct 11, 2019

tags | headline, malware, phone, russia, cyberwar, spyware, backdoor
Apple Drops Hong Kong Police Tracking App Used By Protesters
Posted Oct 10, 2019

tags | headline, government, phone, china, cyberwar, apple
Forum Cracks The Vintage Passwords Of Ken Thompson And Other Unix Pioneers
Posted Oct 10, 2019

tags | headline, password
View More News →
packet storm

© 2019 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close