Note: This is an archival copy of Security Sun Alert 200838 as previously published on http://sunsolve.sun.com. Latest version of this security advisory is available from http://support.oracle.com as Sun Alert 1000631.1. |
Category Security Release Phase Resolved StarOffice 8 Software Bug Id 6520258 Date of Workaround Release 10-APR-2007 Date of Resolved Release 17-MAY-2007 Impact Due to a security vulnerability in StarOffice/StarSuite 8, manipulated WordPerfect files, which may have been provided by a local or remote untrusted user, may lead to heap overflow and arbitrary code execution. This issue is described in the following documents:
Contributing Factors This issue can occur in the following releases: SPARC Platform
x86 Platform
Linux Platform
Windows Platform
Note: StarOffice/StarSuite versions 6.0 and 7 are not impacted by this issue. To determine the version of StarOffice installed on a system, the following command can be run (for /<staroffice program dir>/program/bootstraprc): % cat bootstraprc | grep Product ProductKey=StarOffice 8 ProductPatch=(Product Update 2) On the Windows platform, using the GUI, do the following (with StarOffice/StarSuite open):
The version is displayed first in the "about" text. Symptoms There are no predictable symptoms that would indicate the described issue has occurred. Workaround To work around the described issue, only load WordPerfect files from known sources. Resolution This issue is addressed in the following releases: SPARC Platform
x86 Platform
Linux Platform
Windows Platform
Modification History Date: 17-MAY-2007
References120191-09120189-10 120187-09 120185-10 120188-09 120184-09 120186-10 120190-10 Attachments This solution has no attachment |
|