SuSE 11 Security Update : OpenOffice_org (SAT Patch Number 1258)

high Nessus Plugin ID 41361

Synopsis

The remote SuSE 11 host is missing one or more security updates.

Description

This update of OpenOffice.org fixes potential buffer overflow in EMF parser code (enhwmf.cxx, emfplus.cxx) (Thanks to Petr Mladek).
Additionally Secunia reported an integer underflow (CVE-2009-0200) and a buffer overflow (CVE-2009-0201) that could be triggered while parsing Word documents.

Also provides the maintenance update to OpenOffice.org-3.1.1.

Details about all upstream changes can be found at http://development.openoffice.org/releases/3.1.1.html

Solution

Apply SAT patch number 1258.

See Also

https://bugzilla.novell.com/show_bug.cgi?id=522833

https://bugzilla.novell.com/show_bug.cgi?id=523005

https://bugzilla.novell.com/show_bug.cgi?id=523191

https://bugzilla.novell.com/show_bug.cgi?id=523414

https://bugzilla.novell.com/show_bug.cgi?id=523603

https://bugzilla.novell.com/show_bug.cgi?id=523852

https://bugzilla.novell.com/show_bug.cgi?id=524215

https://bugzilla.novell.com/show_bug.cgi?id=525633

https://bugzilla.novell.com/show_bug.cgi?id=525635

https://bugzilla.novell.com/show_bug.cgi?id=525642

https://bugzilla.novell.com/show_bug.cgi?id=525647

https://bugzilla.novell.com/show_bug.cgi?id=525649

https://bugzilla.novell.com/show_bug.cgi?id=526004

https://bugzilla.novell.com/show_bug.cgi?id=526342

https://bugzilla.novell.com/show_bug.cgi?id=527356

https://bugzilla.novell.com/show_bug.cgi?id=529208

https://bugzilla.novell.com/show_bug.cgi?id=529532

https://bugzilla.novell.com/show_bug.cgi?id=531221

http://support.novell.com/security/cve/CVE-2009-0200.html

http://support.novell.com/security/cve/CVE-2009-0201.html

https://bugzilla.novell.com/show_bug.cgi?id=249775

https://bugzilla.novell.com/show_bug.cgi?id=377727

https://bugzilla.novell.com/show_bug.cgi?id=403402

https://bugzilla.novell.com/show_bug.cgi?id=417818

https://bugzilla.novell.com/show_bug.cgi?id=433834

https://bugzilla.novell.com/show_bug.cgi?id=437666

https://bugzilla.novell.com/show_bug.cgi?id=443361

https://bugzilla.novell.com/show_bug.cgi?id=462657

https://bugzilla.novell.com/show_bug.cgi?id=464568

https://bugzilla.novell.com/show_bug.cgi?id=478583

https://bugzilla.novell.com/show_bug.cgi?id=478945

https://bugzilla.novell.com/show_bug.cgi?id=478972

https://bugzilla.novell.com/show_bug.cgi?id=478977

https://bugzilla.novell.com/show_bug.cgi?id=479062

https://bugzilla.novell.com/show_bug.cgi?id=479834

https://bugzilla.novell.com/show_bug.cgi?id=480229

https://bugzilla.novell.com/show_bug.cgi?id=480243

https://bugzilla.novell.com/show_bug.cgi?id=480324

https://bugzilla.novell.com/show_bug.cgi?id=483951

https://bugzilla.novell.com/show_bug.cgi?id=485609

https://bugzilla.novell.com/show_bug.cgi?id=485637

https://bugzilla.novell.com/show_bug.cgi?id=485645

https://bugzilla.novell.com/show_bug.cgi?id=491898

https://bugzilla.novell.com/show_bug.cgi?id=495140

https://bugzilla.novell.com/show_bug.cgi?id=497559

https://bugzilla.novell.com/show_bug.cgi?id=497560

https://bugzilla.novell.com/show_bug.cgi?id=497563

https://bugzilla.novell.com/show_bug.cgi?id=497570

https://bugzilla.novell.com/show_bug.cgi?id=498737

https://bugzilla.novell.com/show_bug.cgi?id=499124

https://bugzilla.novell.com/show_bug.cgi?id=499129

https://bugzilla.novell.com/show_bug.cgi?id=499131

https://bugzilla.novell.com/show_bug.cgi?id=500175

https://bugzilla.novell.com/show_bug.cgi?id=502090

https://bugzilla.novell.com/show_bug.cgi?id=502173

https://bugzilla.novell.com/show_bug.cgi?id=502717

https://bugzilla.novell.com/show_bug.cgi?id=503482

https://bugzilla.novell.com/show_bug.cgi?id=504623

https://bugzilla.novell.com/show_bug.cgi?id=504827

https://bugzilla.novell.com/show_bug.cgi?id=505704

https://bugzilla.novell.com/show_bug.cgi?id=505917

https://bugzilla.novell.com/show_bug.cgi?id=506095

https://bugzilla.novell.com/show_bug.cgi?id=507400

https://bugzilla.novell.com/show_bug.cgi?id=507501

https://bugzilla.novell.com/show_bug.cgi?id=507643

https://bugzilla.novell.com/show_bug.cgi?id=507745

https://bugzilla.novell.com/show_bug.cgi?id=507748

https://bugzilla.novell.com/show_bug.cgi?id=507758

https://bugzilla.novell.com/show_bug.cgi?id=507760

https://bugzilla.novell.com/show_bug.cgi?id=507768

https://bugzilla.novell.com/show_bug.cgi?id=508101

https://bugzilla.novell.com/show_bug.cgi?id=508113

https://bugzilla.novell.com/show_bug.cgi?id=508621

https://bugzilla.novell.com/show_bug.cgi?id=508867

https://bugzilla.novell.com/show_bug.cgi?id=508872

https://bugzilla.novell.com/show_bug.cgi?id=509209

https://bugzilla.novell.com/show_bug.cgi?id=509768

https://bugzilla.novell.com/show_bug.cgi?id=510003

https://bugzilla.novell.com/show_bug.cgi?id=510168

https://bugzilla.novell.com/show_bug.cgi?id=511006

https://bugzilla.novell.com/show_bug.cgi?id=512060

https://bugzilla.novell.com/show_bug.cgi?id=512146

https://bugzilla.novell.com/show_bug.cgi?id=514085

https://bugzilla.novell.com/show_bug.cgi?id=514089

https://bugzilla.novell.com/show_bug.cgi?id=514151

https://bugzilla.novell.com/show_bug.cgi?id=514156

https://bugzilla.novell.com/show_bug.cgi?id=514164

https://bugzilla.novell.com/show_bug.cgi?id=514395

https://bugzilla.novell.com/show_bug.cgi?id=514944

https://bugzilla.novell.com/show_bug.cgi?id=516406

https://bugzilla.novell.com/show_bug.cgi?id=518426

https://bugzilla.novell.com/show_bug.cgi?id=518731

https://bugzilla.novell.com/show_bug.cgi?id=518741

https://bugzilla.novell.com/show_bug.cgi?id=519201

https://bugzilla.novell.com/show_bug.cgi?id=520228

https://bugzilla.novell.com/show_bug.cgi?id=520556

https://bugzilla.novell.com/show_bug.cgi?id=521447

https://bugzilla.novell.com/show_bug.cgi?id=521624

https://bugzilla.novell.com/show_bug.cgi?id=521820

Plugin Details

Severity: High

ID: 41361

File Name: suse_11_OpenOffice_org-090829.nasl

Version: 1.11

Type: local

Agent: unix

Published: 9/24/2009

Updated: 1/14/2021

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:11:openoffice_org-impress-extensions, p-cpe:/a:novell:suse_linux:11:openoffice_org-kde, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-af, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-ar, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-ca, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-cs, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-da, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-de, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-el, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-en-gb, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-es, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-extras, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-fi, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-fr, p-cpe:/a:novell:suse_linux:11:openoffice_org, p-cpe:/a:novell:suse_linux:11:openoffice_org-languagetool, p-cpe:/a:novell:suse_linux:11:openoffice_org-languagetool-de, p-cpe:/a:novell:suse_linux:11:openoffice_org-languagetool-en, p-cpe:/a:novell:suse_linux:11:openoffice_org-languagetool-es, p-cpe:/a:novell:suse_linux:11:openoffice_org-languagetool-fr, p-cpe:/a:novell:suse_linux:11:openoffice_org-languagetool-it, p-cpe:/a:novell:suse_linux:11:openoffice_org-languagetool-nl, p-cpe:/a:novell:suse_linux:11:openoffice_org-languagetool-pl, p-cpe:/a:novell:suse_linux:11:openoffice_org-languagetool-sv, p-cpe:/a:novell:suse_linux:11:openoffice_org-base, p-cpe:/a:novell:suse_linux:11:openoffice_org-base-drivers-postgresql, p-cpe:/a:novell:suse_linux:11:openoffice_org-base-extensions, p-cpe:/a:novell:suse_linux:11:openoffice_org-calc, p-cpe:/a:novell:suse_linux:11:openoffice_org-calc-extensions, p-cpe:/a:novell:suse_linux:11:openoffice_org-components, p-cpe:/a:novell:suse_linux:11:openoffice_org-draw, p-cpe:/a:novell:suse_linux:11:openoffice_org-draw-extensions, p-cpe:/a:novell:suse_linux:11:openoffice_org-filters, p-cpe:/a:novell:suse_linux:11:openoffice_org-filters-optional, p-cpe:/a:novell:suse_linux:11:openoffice_org-gnome, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-ar, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-cs, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-da, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-de, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-en-gb, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-en-us, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-en-us-devel, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-es, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-fr, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-gu-in, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-hi-in, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-hu, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-it, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-ja, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-ko, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-nl, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-pl, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-pt, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-pt-br, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-ru, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-sv, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-zh-cn, p-cpe:/a:novell:suse_linux:11:openoffice_org-help-zh-tw, p-cpe:/a:novell:suse_linux:11:openoffice_org-icon-themes, p-cpe:/a:novell:suse_linux:11:openoffice_org-impress, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-zh-tw, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-zu, p-cpe:/a:novell:suse_linux:11:openoffice_org-libs-core, p-cpe:/a:novell:suse_linux:11:openoffice_org-libs-extern, p-cpe:/a:novell:suse_linux:11:openoffice_org-libs-gui, p-cpe:/a:novell:suse_linux:11:openoffice_org-mailmerge, p-cpe:/a:novell:suse_linux:11:openoffice_org-math, p-cpe:/a:novell:suse_linux:11:openoffice_org-mono, p-cpe:/a:novell:suse_linux:11:openoffice_org-officebean, p-cpe:/a:novell:suse_linux:11:openoffice_org-pyuno, p-cpe:/a:novell:suse_linux:11:openoffice_org-ure, p-cpe:/a:novell:suse_linux:11:openoffice_org-writer, p-cpe:/a:novell:suse_linux:11:openoffice_org-writer-extensions, cpe:/o:novell:suse_linux:11, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-gu-in, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-hi-in, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-hu, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-it, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-ja, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-ko, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-nb, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-nl, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-nn, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-pl, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-pt, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-pt-br, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-ru, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-sk, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-sv, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-xh, p-cpe:/a:novell:suse_linux:11:openoffice_org-l10n-zh-cn

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 8/29/2009

Reference Information

CVE: CVE-2009-0200, CVE-2009-0201

CWE: 119, 189