Sean Larsson found a heap overflow flaw in the OpenOffice memory allocator. An attacker could create a carefully crafted file that could cause OpenOffice.org to crash or possibly execute arbitrary code if the file was opened by a victim. (CVE-2008-2152) This probably affects all OpenOffice shipped in RHEL3,4,5 Embargo is Jun 10 or 11 (2.4.1 release of OpenOffice.org)
Created attachment 308679 [details] oo2 patch from caolan
Created attachment 308680 [details] oo1.1 backported patch from caolan
opening bug, now public at: http://www.openoffice.org/security/cves/CVE-2008-2152.html
openoffice.org-2.4.1-17.3.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
openoffice.org-2.3.0-6.15.fc8 has been submitted as an update for Fedora 8
openoffice.org-2.3.0-6.9.fc7 has been submitted as an update for Fedora 7
openoffice.org-2.3.0-6.9.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
openoffice.org-2.3.0-6.15.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
This issue was addressed in: Red Hat Enterprise Linux: http://rhn.redhat.com/errata/RHSA-2008-0537.html http://rhn.redhat.com/errata/RHSA-2008-0538.html Fedora: https://admin.fedoraproject.org/updates/F7/FEDORA-2008-5239 https://admin.fedoraproject.org/updates/F8/FEDORA-2008-5247 https://admin.fedoraproject.org/updates/F9/FEDORA-2008-5143