OpenOffice Information Leakage Vulnerability (CVE-2014-3575)
Release date:
Updated on:
Affected Systems:
OpenOffice
Unaffected system:
OpenOffice <= 4.1.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 69354
CVE (CAN) ID: CVE-2014-3575
OpenOffice was originally Sun's commercial Office software-StarOffice. After Sun's public code, it was officially named OpenOffice development plan.
When OLE preview is generated in OpenOffice 4.1.0 and earlier versions, arbitrary file data is inserted into the open construction document. After the updated document is transmitted to other parties, there is an information leakage vulnerability in implementation. Attackers can exploit this vulnerability to obtain sensitive information.
<* Source: Open-Xchange
Link: http://seclists.org/bugtraq/2014/Aug/114
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
OpenOffice
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.openoffice.org/security
This article permanently updates the link address: