Description: Some vulnerabilities have been reported in OpenOffice, which can potentially be exploited by malicious people to compromise a user's system.
1) An error exists when parsing the "prdata" tag in RTF files where the first token is smaller that the second one. This can be exploited to cause a heap-based buffer overflow by e.g. tricking a user into opening a specially crafted RTF files.
2) A vulnerability is caused due to the use of a vulnerable copy of the FreeType library, which can be exploited to cause a heap based buffer overflow by e.g. tricking a user into opening a specially crafted document.
Successful exploitation may allow the execution of arbitrary code.
Solution: Update to version 2.2.1.
Provided and/or discovered by: 1) John Heasman, NGSSoftware
2) Originally reported in the FreeType library by Victor Stinner (INL)
Changelog: 2007-06-14: Updated advisory with new information from NGSSoftware. Added vulnerability #2 and CVE reference. Added links to OpenOffice.org and NGSoftware. Updated "Solution" section.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.