Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2009-2140

Published: 21 September 2009

Multiple heap-based buffer overflows in cppcanvas/source/mtfrenderer/emfplus.cxx in Go-oo 2.x and 3.x before 3.0.1, previously named ooo-build and related to OpenOffice.org (OOo), allow remote attackers to execute arbitrary code via a crafted EMF+ file, a similar issue to CVE-2008-2238.

Notes

AuthorNote
jdstrand
Patch is patches/emf+/emf+-cppcanvas-input-validation.diff, but
emfplus.cxx is not included or compiled in Ubuntu 8.10 or 8.04. Debian
includes the patch in 2.4.1+dfsg-1+lenny3, but does not apply it anywhere.

Priority

Medium

Status

Package Release Status
openoffice.org
Launchpad, Ubuntu, Debian
dapper Ignored
(end of life)
hardy Not vulnerable
(code not present)
intrepid Not vulnerable
(code not present)
jaunty Not vulnerable
(3.0.1-9ubuntu3)
upstream
Released (3.0.1)
Patches:
upstream: http://cgit.freedesktop.org/ooo-build/ooo-build/commit/?id=49b4e38571912a7d28c4044e5b2bd57e51c77d55