OpenOffice Reveals Motivation for Security Updates

Sep 09, 2009

Earlier than previously announced, the OpenOffice Project has released information regarding the newest security updates, spurred on due to gaps in security.

The software project team has advised users of the various release branches of versions 3 and 2 to update their software as soon as possible. More detailed information regarding these security loopholes were planned for September 11, but this info has been made public already.

The first security vulnerability (CVE-2009-0200 and CVE-2009-0201
concerns the processing of data in the format Windows meta-file (WMF). Manipulated data in graphic format could trigger heap overflows and under certain circumstances allow infiltrated code to execute under the authority of Office users. This issue was discovered by Dyon Balding from the company Secunia Research. This loophole also affects every version of Open Office 1.

The second loophole (CVE-2009-2414 and CVE-2009-2416 affects the processing of XML documents, including those in Open Document format (ODF). A targeted XML document could cause malicious code to execute.

Neither of the potential vulnerabilities have met with a real exploit of security to date. The most certain of solutions is to install either Open Office 3.1.1 or 2.4.3. which are the most current versions of the software.

Related content

  • End of OpenOffice?

    The Apache Software Foundation considers retiring OpenOffice

  • OpenOffice 3.2 Available

    Just in time for the tenth year anniversary of the free office suite is the complete release of OpenOffice 3.2.

  • The Clear Choice

    While LibreOffice and OpenOffice have a shared past, LibreOffice outstrips OpenOffice in contributors, code commits, and features.

  • Sun Developer on the Security of OpenOffice

    In a recent blog, Sun developer Malte Timmermann took a position on the security concerns of the Ecole Superieure d'Informatique, Electronique, Automatique (ESIEA) in Paris-Laval, France. The subject was the vulnerability of OpenOffice, involving document macros, for example.

  • Open Office 2.3.1 Removes Bugs

    The latest version of the office suite, version 2.3.1, removes bugs and closes vulnerabilities.

comments powered by Disqus
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters

Support Our Work

Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.

Learn More