On CBS MoneyWatch: 11 Buzzwords That Should Be Banned
BNET Business Network:
BNET
TechRepublic
ZDNet

By Liam Tung , ZDNet Australia
Posted on ZDNet News: Sep 25, 2007 8:38:00 AM

Security experts have discovered vulnerabilities in OpenOffice.org that could allow attackers to remotely execute code on Linux, Windows or Apple Mac-based computers.

OpenOffice version 2.0.4 and earlier versions are vulnerable to maliciously crafted TIFF files, which can be delivered in an e-mail attachment, published on a Web site or shared using peer-to-peer software. The next version of OpenOffice (version 2.3) arrived on September 17 and is not affected by the flaw.

The vulnerability was discovered by researchers at iDefense, who claim that the OpenOffice TIFF parsing code is flawed.

"When parsing the TIFF directory entries for certain tags, the parser uses untrusted values from the file to calculate the amount of memory to allocate. By providing specially crafted values, an integer overflow occurs in this calculation. This results in the allocation of a buffer of insufficient size, which in turn leads to a heap overflow," the iDefense team reported last Friday.

TrustDefender co-founder Andreas Baumhof said: "This vulnerability allows someone to execute malicious code on your computer. It's an OpenOffice bug so it doesn't matter what type of operating system you run; it allows you to run malicious software with the same rights as the user who runs OpenOffice."

"At this stage, it's only confirmed on Linux," Baumhof said. "But typically it would affect all operating systems. The only difference with Linux and Windows is that home users typically run Windows as the administrator."

In June, OpenOffice users were warned about a worm called "Badbunny" that was spreading in the wild through multiple operating systems, including Mac OS, Windows and Linux.

At the time, Symantec posted an advisory that said: "A new worm is being distributed within malicious OpenOffice documents. The worm can infect Windows, Linux and Mac OS X systems. Be cautious when handling OpenOffice files from unknown sources".

Liam Tung of ZDNet Australia reported from Sydney.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 89 Talkback(s)
Sure...
So, a bug like this in Office would of been patched too.Yes, of course.

In January....

silly... (Read the rest)
Posted by: dalecosp Posted on: 10/09/07 You are currently: a Guest | | Terms of Use
OpenOffice bug hits multiple operating systems  Loverock Davidson | 09/25/07
Right  rbeier | 09/25/07
Good response. Absolutely correct.  Cayble | 09/29/07
1 bug versus  Linux User 147560 | 09/25/07
I think he was picking more on the ....  socialism=nowhere | 09/26/07
Bugs Bugs Bugs  chromeronin | 09/26/07
Whatever  rkuhn040172@... | 09/26/07
Errrmmm, you mean Microsoft Update...  burkhartmic | 09/26/07
chuckle  boguscomputer | 09/27/07
Sure...  dalecosp | 10/09/07
office2003 servcie pack3 you would be talking about not 8 chromeronin  SO.CAL Guy | 09/27/07
how many for Microsoft Office? Grow up already.  zcaveman | 09/26/07
Outlook? Good?  Filker0_z | 09/26/07
Well if it's just e-mail...  NCWeber_z@... | 09/26/07
Please  notsofast | 09/26/07
Perfect security model?  Filker0_z | 09/26/07
The difference  Hrothgar - PCLinuxOS User | 10/03/07
You have it mostly right  Boot_Agnostic | 09/25/07
I think that was his point...  socialism=nowhere | 09/26/07
Or just upgrade to the current version. [NT]  swoopee | 09/25/07
Same problem as the Win9x folks  magcomment | 09/25/07
With the Exception...  rkuhn040172@... | 09/26/07
LOL......  socialism=nowhere | 09/26/07
On the other hand......  Ole Man | 09/26/07
Bugs?  NCWeber_z@... | 09/26/07
Obviously,  alaniane@... | 09/27/07
Easiest solution -- don't open TIFF files  critic-at-arms | 09/27/07
So did the MS Word Basic macro viruses....  jlafitte | 09/28/07
If I had a dollar for every bug in Linux  ja4509 | 10/04/07
OpenOffice has bugs? No surprise.  pmoralee@... | 10/04/07
No story here...  Technocrat@... | 09/25/07
I have only one question...  Linux User 147560 | 09/25/07
Faxes  Whyaylooh | 09/25/07
We have a FAX machine dedicated to that  Linux User 147560 | 09/25/07
Olympus cameras  Jack-Booted EULA | 09/25/07
Anyone using a scanner or fax...  bjbrock | 09/25/07
My scanner  Linux User 147560 | 09/25/07
No your not odd. A bit...  bjbrock | 09/26/07
Who uses .tiffs?  labarker | 09/26/07
tiff is still widely used  woot! | 09/26/07
I don't think gif is lossy  benallgor@... | 09/26/07
Way off base, dude.  TechinMN | 09/26/07
Uh since most Linux users DO NOT  Linux User 147560 | 09/27/07
Re:  rkuhn040172@... | 09/26/07
Faxing!  rkuhn040172@... | 09/26/07
At a major corporation  Linux User 147560 | 09/27/07
Exasberated gasping...  Chippolus | 09/26/07
Who uses TIFFs?  MikeMoyle | 09/26/07
That would explain it then  Linux User 147560 | 09/27/07
This is news?  Henaway | 09/25/07
Exactly! this is not news-worthy  parabyte | 09/26/07
Your Ignorance  rkuhn040172@... | 09/26/07
Free upgrades? I've had to pay for mine over the years.  martinfam@... | 09/26/07
For me  alaniane@... | 09/27/07
Rant, froth, freak out, etc.  NonZealot | 09/25/07
Sure you can run non-exec files in Unix  magcomment | 09/25/07
Did you even read the article?  SpikeyMike | 09/25/07
Exactly!  rkuhn040172@... | 09/26/07
To both who replied  NonZealot | 09/25/07
I guess we could call this  Shelendrea | 09/25/07
AMEN - but for the dummies "it's a flaw, the sky is falling,  socialism=nowhere | 09/26/07
True  rkuhn040172@... | 09/26/07
If it's a virus/trojan  alaniane@... | 09/27/07
FUD  Sodbuster41 | 09/26/07
Having a hard time with the contents....bucko.  socialism=nowhere | 09/26/07
You're Retard  rkuhn040172@... | 09/26/07
This was FIXED MONTHS AGO  kbaily05@... | 09/26/07
No lack of comprehension here cool  btljooz | 09/26/07
Well DRAT!!! blush ...this was SUPPOSED to  btljooz | 09/26/07
He's one of a new breed  Ole Man | 09/26/07
RE: OpenOffice bug hits multiple operating systems  tracy anne | 09/26/07
All software has bugs...  LilBambi_z | 09/26/07
Apparmour  chromeronin | 09/26/07
Spelling  chromeronin | 09/26/07
Nobody should be such an old version anyway...  carbonred | 09/26/07
Ope, it's super-fud time...  tek_heretik | 09/26/07
A magnifying glass and a spotlight would make...  tek_heretik | 09/26/07
so, lets count the bugs of open office to MS office  DanLM | 09/26/07
NEXT !  frankyvee | 09/26/07
Story dated, no problem with OpenOffice  gilhardwick@... | 09/26/07
Actually  putt1ck | 09/27/07
Somewhat irresponsible reporting  Filker0_z | 09/26/07
RE: OpenOffice bug hits multiple operating systems  chris.copp@... | 09/27/07
Obviously not a programmer, and very ill informed  tracy anne | 09/27/07
MS/ZDNet FUD Machine  Too_Busy_To_Be_Here | 09/27/07
RE: OpenOffice bug hits multiple operating systems  ibnanouk | 09/28/07
Open anything and Hackers  bubasan | 09/29/07
HACKERS & VIRUS'  manie3844@... | 09/30/07
Windows 3.1 buggy too...  Twong_SNG | 10/01/07

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here