ITS Homepage Click here for text version of ITS homepage University at AlbanyUAlbany Site IndexUAlbany Search
alerts_tag

Vulnerability in OpenOffice


ALARM Group ALERT - click for a description of ALARM, The Computing Alert System


Alert Number: 120607-01
Alert Date:  12/06/07
Alert Title:  Vulnerability in OpenOffice
Update-to:  None
OS/Platform/Application:
OpenOffice.org suite version <2.3.1
OpenOffice HSQLDB version <1.8.0.9
Category:  ALERT
Severity:  HIGH
Attention:  System Administrators, Desktop Support Personnel, OpenOffice Users

Summary:  Internet Security-Related Agencies are currently reporting the existence of a vulnerability in the HSQLDB (the default database engine) component of OpenOffice.org.  A likely vector of exploit for this vulnerability is the opening of a specifically-crafted database document.  This vulnerability is rated as "highly critical" by at least one Agency.  An updated version of OpenOffice.org (that includes a new version of HSQLDB) is available from the vendor to address this vulnerability.

Recommended Actions:  Persons who manage, maintain or use OpenOffice.org are encouraged to read the update information (including any associated caveats, system requirements, etc) and (if appropriate) apply the upgrade immediately as per the instructions provided by the vendor. 

Readers are encouraged to share this alert with family, friends, and associates who may use OpenOffice on their home PCs.

ITS Actions:  At this time, ITS is taking no specific additional actions to address this software update release.

Resources:

OpenOffice security advisory:
http://www.openoffice.org/security/cves/CVE-2007-4575.html

Secunia Advisory:
http://secunia.com/advisories/27928/

OpenOffice.org download page:
http://www.openoffice.org/index.html

 

BLANKABCDEFGHIJKLMBLANK
BLANKNOPQRSTUVWXYZBLANK
CHOOSE FROM the ITS Site Index

GO TO an ITS Group

Information Technology Services
University at Albany, SUNY
1400 Washington Avenue
Albany, NY 12222
ITS Service Centers:  518-442-4000
 
University at Albany Home Page
Contact UAlbany | Directories | Calendars | Visitors | Site Index | Search
Admissions | Academics | Research | IT Services | Libraries | Athletics

Internet Privacy Policy              IT Policies