CVE-2013-2189: OpenOffice DOC Memory Corruption Vulnerability

2013-07-25 Thread Herbert Duerr
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2013-2189 OpenOffice DOC Memory Corruption Vulnerability Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache OpenOffice 3.4.0 to 3.4.1 on all platforms. Predecessor versions of OpenOffice.org may be also

CVE-2013-4156: OpenOffice DOCM Memory Corruption Vulnerability

2013-07-25 Thread Herbert Duerr
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2013-4156 OpenOffice DOCM Memory Corruption Vulnerability Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache OpenOffice 3.4.0 and 3.4.1, on all platforms. Predecessor versions of OpenOffice.org may be a

Re: AOO 400 Writer Bugs, rev. email 2013-08-12; former: AOO Bugzilla Bug 122948 - Copy/pasting some Punjabi strings AOO 4.0.0 crashes, Writer 3.4.1 works correctly

2013-08-13 Thread Herbert Duerr
Hi Robert, On 12.08.2013 18:02, Robert Hupp wrote: Dear AOO400 workers, not only Punjabi strings seem to be crucial for crashing. When pasting the following string (ref.: http://de.wikipedia.org/wiki/Amazonas or: http://en.wikipedia.org/wiki/Amazon_River ) /*in parts, leaving crucial substrings

CVE-2014-3524: Apache OpenOffice Calc Command Injection Vulnerability

2014-08-21 Thread Herbert Duerr
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2014-3524 OpenOffice Calc Command Injection Vulnerability Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache OpenOffice 4.1.0 and older on Windows. OpenOffice.org versions may also be affected. D

CVE-2014-3575:OpenOffice Targeted Data Exposure Using Crafted OLE Objects

2014-08-21 Thread Herbert Duerr
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2014-3575 OpenOffice Targeted Data Exposure Using Crafted OLE Objects Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache OpenOffice 4.1.0 and older on Windows. OpenOffice.org versions are also aff

CVE-2015-1774: OpenOffice HWP Filter Remote Execution and DoS Vulnerability

2015-04-25 Thread Herbert Duerr
CVE-2015-1774 OpenOffice HWP Filter Remote Code Execution and Denial of Service Vulnerability A vulnerability in OpenOffice's HWP filter allows attackers to cause a denial of service (memory corruption and application crash) or possibly execution of arbitrary code by preparing specially crafted d