Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2009-3569

Published: 6 October 2009

Stack-based buffer overflow in OpenOffice.org (OOo) allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka "Client-side stack overflow exploit." NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

Notes

AuthorNote
jdstrand
not enough information to do anything. Defer until more information
becomes available
mdeslaur
still no info as of 2010-11-11, also probably mitigated by
stack protector, downgrading to low
jdstrand
still no information. Due to stack overflow, marking as protected
(just a crasher) and ignoring. Can reopen once more info is available

Priority

Negligible

Status

Package Release Status
libreoffice
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Does not exist

intrepid Does not exist

jaunty Does not exist

karmic Does not exist

lucid Does not exist

maverick Does not exist

natty Ignored

upstream Needs triage

openoffice.org
Launchpad, Ubuntu, Debian
dapper Ignored
(end of life)
hardy Ignored
(end of life)
intrepid Ignored
(end of life)
jaunty Ignored
(end of life)
karmic Ignored
(end of life)
lucid Ignored

maverick Ignored

natty Not vulnerable
(transitional package)
upstream Needs triage

This vulnerability is mitigated in part by the use of gcc's stack protector in Ubuntu.