|
Sun StarOffice Office Suite TIFF Parsing Integer Overflow Vulnerabilities
|
|
Secunia Advisory:
|
SA26891
|
|
|
Release Date:
|
2007-09-25
|
|
Popularity:
|
4,167 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | StarOffice / StarSuite 7.x StarOffice / StarSuite 8.x StarOffice 6.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2007-2834
|
|
Description: Sun has acknowledged a vulnerability in Sun StarOffice, which potentially can be exploited by malicious people to compromise a user's system.
The vulnerabilities are caused due to integer overflows when processing certain tags within TIFF images. This can be exploited to cause heap-based buffer overflows by e.g. tricking a user into opening a specially crafted document.
Successful exploitation may allow the execution of arbitrary code.
For more information:
SA26816
The vulnerabilities are reported in StarOffice 6.0 Office Suite, StarOffice 7 Office Suite, and StarOffice 8 Office Suite.
Solution: Apply patches.
-- SPARC Platform --
StarOffice/StarSuite 6.0:
Apply patch 112885-09 or later
StarOffice/StarSuite 7:
Apply patch 116519-15 or later
StarOffice 8:
Apply patch 120185-12 or later
StarSuite 8:
Apply patch 120189-12 or later
-- x86 Platform --
StarOffice/StarSuite 6.0:
Apply patch 112886-09 or later
StarOffice/StarSuite 7:
Apply patch 117073-13 or later
StarOffice 8:
Apply patch 120186-12 or later
StarSuite 8:
Apply patch 120190-12 or later
-- Linux Platform --
StarOffice/StarSuite 6.0:
Apply patch 112887-09 or later
StarOffice/StarSuite 7:
Apply patch 116518-15 or later
StarSuite 8:
Apply patch 120184-11 or later
StarOffice 8:
Apply patch 120188-11 or later
-- Windows Platform --
StarOffice/StarSuite 6.0:
Apply patch 112888-09 or later
StarOffice/StarSuite 7:
Apply patch 116520-14 or later
StarOffice 8:
Apply patch 120187-11 or later
StarSuite 8:
Apply patch 120191-11 or later
Provided and/or discovered by: Discovered by an anonymous researcher and reported via iDefense Labs.
Original Advisory: Sun:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102994-1
iDefense Labs:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=593
Other References: SA26816:
http://secunia.com/advisories/26816/
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|