OpenOffice Meta Character Remote Shell Command Execution Vulnerability
BID:22812
Info
OpenOffice Meta Character Remote Shell Command Execution Vulnerability
| Bugtraq ID: | 22812 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0239 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2007 12:00AM |
| Updated: | May 24 2007 07:22PM |
| Credit: | This issue was reported by the vendor. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 Sun StarSuite 8 Update 6 Sun StarSuite 7 PP9 Sun StarSuite 7 Sun StarSuite 6 PP6 Sun StarSuite 6 Sun StarOffice 7.0 Sun StarOffice 8 Update 6 Sun StarOffice 7.0 PP9 Sun StarOffice 6.0 PP6 Sun StarOffice 6.0 SGI ProPack 3.0 SP6 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux Desktop 9 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux 9.3 x86 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86 rPath rPath Linux 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux Optional Productivity Application 5 server RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Desktop 4.0 RedHat Desktop 3.0 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Pardus Linux 2007.1 OpenOffice OpenOffice 2.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Gentoo app-office/openoffice-bin 2.1 Gentoo app-office/openoffice 2.0.3 Foresight Linux Foresight Linux 1.1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Interactive Response 2.0 |
| Not Vulnerable: |
Gentoo app-office/openoffice-bin 2.2 Gentoo app-office/openoffice 2.1.0-r1 |
Discussion
Exploit / POC
OpenOffice Meta Character Remote Shell Command Execution Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to open a malicious document and follow a specially crafted link.
To exploit this issue, an attacker must entice an unsuspecting user to open a malicious document and follow a specially crafted link.
Solution / Fix
OpenOffice Meta Character Remote Shell Command Execution Vulnerability
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Sun StarSuite 7
Sun StarOffice 6.0 PP6
Sun StarSuite 8 Update 6
Sun StarOffice 7.0 PP9
Sun StarSuite 6
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Sun StarSuite 7
-
Sun 116518-13
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -116518-13-1 -
Sun 116519-13
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -116519-13-1 -
Sun 120185-10
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -120185-10-1 -
Sun 120188-09
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -120188-09-1
Sun StarOffice 6.0 PP6
-
Sun 112885-07
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -112885-07-1 -
Sun 112886-07
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -112886-07-1 -
Sun 112887-07
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -112887-07-1
Sun StarSuite 8 Update 6
-
Sun 120184-09
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -120184-09-1 -
Sun 120189-10
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -120187-09-1
Sun StarOffice 7.0 PP9
-
Sun 116518-13
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -116518-13-1 -
Sun 116519-13
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -116519-13-1 -
Sun 117073-11
http://sunsolve.sun.com/search/document.do?assetkey=1-21-117073-11-1&s earchclause=117073-11http://sunsolve.sun.com/search/document.do?assetk ey=1-21-117073-11-1&searchclause=117073-11 -
Sun 120185-10
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -120185-10-1 -
Sun 120188-09
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -120188-09-1
Sun StarSuite 6
References
OpenOffice Meta Character Remote Shell Command Execution Vulnerability
References:
References: