OpenOffice.org bug targets Linux, but Macs and Windows not safe either

Analysis
Sep 25, 20071 min

Security experts have found a vulnerability in the old version of OpenOffice.org that could allow attackers to remote execute code. The good news is that the latest version of OpenOffice was released earlier this month and is not affected by the problem. The vulnerability was only confirmed on Linux, though researchers say that it wouldn’t matter what operating system was being used.

According to a story on ZDNet:

“When parsing the TIFF directory entries for certain tags, the parser uses untrusted values from the file to calculate the amount of memory to allocate. By providing specially crafted values, an integer overflow occurs in this calculation. This results in the allocation of a buffer of insufficient size, which in turn leads to a heap overflow,” the iDefense team reported last Friday.

In June, OpenOffice users were warned about a worm called BadBunny.