Australian IT JOBS : Sydney IT jobs, UNIX jobs, Linux jobs, Java jobs, ASP jobs Linux.conf.au Linux.conf.au
Technology news and Jobs arrow Information Technology News arrow 'Highly critical' update for OpenOffice
'Highly critical' update for OpenOffice PDF Print E-mail
Written by Stephen Withers   
Thursday, 06 December 2007
OpenOffice 2.3.1 fixes a variety of bugs, but one of the most important concerns a vulnerability in the database engine shipped with the package.

A flaw in the HSQLDB database engine could be exploited to execute arbitrary static Java code if an attacker could induce a user to open a maliciously crafted database document.

Secunia rates the vulnerability as 'highly critical'.

OpenOffice 2.3.1 includes HSQLDB 1.8.0.9, which fixes the issue. Any version prior to 2.3.1 should be updated. Since HSQLBD is written in Java, all supported platforms are affected.

Users of OpenOffice derivatives should either watch for a corresponding update or (if necessary) install the revised version of the database which can be downloaded via hsqldb.org.



Get stories like this delivered daily - FREE - subscribe now
When you subscribe get a 12 months license for LiveProject
Valued at $99 USD


LiveWire - Desktop alerts Download the FREE iTWire desktop alert widget LiveWire - Desktop alerts


Del.icio.us!
 
< Prev   Next >

Latest jobs

Contact , Register , Advertise with iTWire , Links , Register , About iTWire , Feedback , Post your jobs , Events , iTWire site map , Start Blogging
Industry Releases , Submit your release now , Start submitting to iTWire , How to post video