Patch issued for OpenOffice.org WMF vulnerability
- 05 January, 2007 09:46
- Comments
A patch has been widely released for a vulnerability in the OpenOffice.org productivity suite, a problem rated as "highly critical" by one security vendor.
The flaw could be exploited by creating a malicious file in the Windows Metafile (WMF) or Enhanced Metafile (EMF) formats. If the file was opened by a user, it could start running unauthorized code on a computer, according to an advisory by Linux distribution vendor Red Hat Inc. which offers the OpenOffice suite with several of its products.
OpenOffice.org is a free software suite that includes a word processor, spreadsheet and a presentation program. It's a competitor to Microsoft's Office suite, although it's not as widely used.
OpenOffice.org has published a patch, which in turn is being distributed by Red Hat.
The problem was first reported in October, but the vendors who distribute OpenOffice -- who often work together on security issues -- opted not to issue the patch until OpenOffice.org acknowledged earlier this week it was a security issue, said Mark Cox [cq], director of Red Hat's Security Response Team.
No public exploits or even proof-of-concept code has been discovered, he added.
Red Hat rated the flaw as only "important" since a user would have to open a malicious file, Cox said. Red Hat users will either receive an update automatically or notification to upgrade their software, he added.
Secunia ApS, however, rated the vulnerability as "highly critical," a rank of "four" on a five-number scale of increasing severity.
The WMF format proved problematic for OpenOffice.org's rival in 2006. After pressure from its customers, Microsoft issued an out-of-cycle patch early last year for its operating systems after widespread attempts to exploit a WMF vulnerability. The flaw -- one of the top security problems of 2006 -- also left Windows systems vulnerable to running code if a malicious WMF was opened.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Process-Driven Master Data Management for Dummies
- Case Study: NZ Bus Develops Applications 60% Faster, Improves Database Performance by up to 35%
- Protecting Against the Leading Causes of Data Breach
- Maximise Software Cost Savings by License Reharvesting, Recycling & Applying Product Use Rights
- Developing an Information Strategy - Strategize, Align, Govern, Execute, and Optimize
-
The NBN, service providers and you... what could go wrong?
-
NBN build gaining momentum daily: Quigley
-
FTC chairman: Do-not-track law may not be needed
-
Kindle sales soar but Amazon mum on actual numbers
-
Wall Street Beat: IPOs, M&A, chip news stir tech optimism
-
MYOB Software for Dummies 6E Australian Edition
-
Windows 7 for Dummies®
-
Windows 7 for Dummies® Dvd+book Bundle
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 for Dummies
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Office 2007 All-In-One Desk Reference for Dummies
-
Teach Yourself Visually Windows 7
-
Microsoft Office









Comments
Post new comment