FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-2238

This CVE name corresponds to:

Entered Topic
2008-11-29 openoffice -- arbitrary code execution vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-2238
Phase Assigned(20080516)

Description

Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow.

References

Source Reference
IDEFENSE 20081031 OpenOffice EMF Record Parsing Multiple Integer Overflow Vulnerabilities
CONFIRM http://www.openoffice.org/security/cves/CVE-2008-2238.html
CONFIRM http://neowiki.neooffice.org/index.php/NeoOffice_2.2.5_Patch_3_New_Features#Security_fixes
DEBIAN DSA-1661
FEDORA FEDORA-2008-9313
FEDORA FEDORA-2008-9333
GENTOO GLSA-200812-13
REDHAT RHSA-2008:0939
SUNALERT 243226
SUSE SUSE-SR:2008:026
UBUNTU USN-677-2
UBUNTU USN-677-1
BID 31962
OVAL oval:org.mitre.oval:def:10849
SECUNIA 32463
SECUNIA 32856
VUPEN ADV-2008-2947
VUPEN ADV-2008-3103
VUPEN ADV-2008-3153
SECTRACK 1021121
SECUNIA 32419
SECUNIA 32461
SECUNIA 32489
SECUNIA 32676
SECUNIA 32872
SECUNIA 33140
XF openoffice-emf-file-bo(46166)