Overview
The OpenOffice.org team has reported a vulnerability in how the 1.1 and 2.0 versions of OpenOffice.org process basic macros.
Description
A vulnerability in OpenOffice.org may allow an attacker to inject basic code into documents such that the code will be executed when the document is loaded. After the document is opened, the user will not be alerted that the macro is running.
|
Impact
A malicious basic macro could change, delete, transmit, overwrite, and read data on the affected computer. It may also be possible for an attacker to remotely execute arbitrary code. |
Solution
Upgrade |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://secunia.com/advisories/20893/
- http://secunia.com/advisories/20867/
- http://secunia.com/advisories/20913/
- http://secunia.com/advisories/20910/
- http://secunia.com/advisories/20975/
- http://www.auscert.org.au/6473
- http://www.debian.org/security/2006/dsa-1104
- http://www.ubuntu.com/usn/usn-313-2
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102490-1
- http://www.openoffice.org/security/CVE-2006-2198.html
Acknowledgements
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2006-2198 |
Date Public: | 2006-06-29 |
Date First Published: | 2006-07-24 |
Date Last Updated: | 2006-07-24 17:42 UTC |
Document Revision: | 23 |