news4geeks.net
17May/120

Apache details OpenOffice 3.4 security fixes


Apache OpenOffice logo Following the release of Apache OpenOffice 3.4.0 last week, the Apache Software Foundation (ASF) has now detailed the security fixes included in the new version of the open source productivity suite. According to the ASF, the first stable release of OpenOffice under its governance addresses a total of three security vulnerabilities, all of which are rated as "important".

These include an integer overflow error when handling embedded images and a memory overwrite bug when loading WordPerfect files, both of which could allow for the execution of arbitrary code. The third hole is related to unchecked memory allocations in malformed PowerPoint files which the developers say could be used to cause a denial of service (DoS). Attacks on all these flaws would require the user to open a specially crafted file. OpenOffice.org 3.3 and the beta version of 3.4 are affected; earlier versions may also be vulnerable. The Security Team advises all users to upgrade to the final 3.4 release.

In a separate announcement, the Apache OpenOffice Project has also published the preliminary download numbers for the 3.4 release. As of Wednesday 16 May, Apache OpenOffice 3.4 had been downloaded more than one million times from over 200 countries – the organisation notes that this figure does not include downloads of language packs, SDKs or source code packages.

Of the downloads, 87% were for Windows and 11% were for Mac OS X. Linux systems accounted for just 2% of the overall downloads, but this could be explained by the fact that a majority of distributions already ship with an office suite out of the box and many users have switched to LibreOffice.

(Source: h-online.com)

 

The ASF (Apache Software Foundation) has approved CloudStack as a TLP (top-level project), helping the open source cloud software effort further establish its independence from Citrix, which acquired ...
READ MORE
Citrix has abandoned its Olympus OpenStack distribution and will focus instead on its open-source CloudStack operating system, which it has contributed as a project under the Apache Software ...
READ MORE
The Apache Software Foundation has confirmed that a new build of the OpenOffice suite will be out next year, and has warned rogue developers that it - and ...
READ MORE
Oracle's MySQL.com customer website was apparently compromised over the weekend by a pair of hackers who publicly posted usernames, and in some cases passwords, of the site's users. Taking ...
READ MORE
Apache helps free CloudStack from Citrix fetters
Citrix abandons OpenStack, takes CloudStack to Apache
Apache confirms new OpenOffice build by 2012
MySQL website falls victim to SQL injection attack

Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

Trackbacks are disabled.