On The Insider: Dr. Conrad Murray Returns to Work
BNET Business Network:
BNET
TechRepublic
ZDNet

September 18th, 2009

Sun patches 'critical' StarOffice/StarSuite flaw

Posted by Ryan Naraine @ 12:30 pm

Categories: Arbitrary Code Execution, Browsers, Complex Attacks, Data theft, Denial of Service (DoS), Exploit code, Open source, Patch Watch

Tags: Sun Microsystems Inc., Flaw, Patch Management, Microsoft Word, Word Processors, Microsoft Office, Security, Office Suites, Software, Ryan Naraine

Sun Microsystems has shipped a fix for a critical vulnerability affecting its StarOffice/StarSuite product lines.

The flaw, which exposes users to code execution attacks, affect StarOffice/StarSuite 7 StarOffice/StarSuite 8 StarOffice/StarSuite 9.

Here’s the Skinny from Sun’s advisory:

A security vulnerability in StarOffice/StarSuite, related to Microsoft Word document handling, may allow a remote unprivileged user to execute arbitrary code on the system with the privileges of a local user running StarOffice/StarSuite, if the local user opens a crafted Microsoft Word document provided by the remote user.

Dyon Balding of Secunia Research is credited for finding and reporting the issue to Sun.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 7 Talkback(s)
RE: Sun patches 'critical' StarOffice/StarSuite flaw
Question to StarOffice/StarSuite users. I product manage a security product for Windows computers called AppGuard. It occurs to me that our QA staff probably hasn't tested explicitly for any problem... (Read the rest)
Posted by: eiverson@... Posted on: 09/21/09 You are currently: a Guest | | Terms of Use
Sun patches Openoffice.org with 3.1.1  21_years_IT | 09/18/09
Open_Office is FREE  Christian_<>< | 09/18/09
So, Linux invulnerable to this?  honeymonster | 09/19/09
Depends...  privatejarhead | 09/19/09
Yup, depends on exploit. Fail on root/Linux  honeymonster | 09/19/09
RE:Yup, depends on exploit. Fail on root/Linux  richdave | 09/21/09
RE: Sun patches 'critical' StarOffice/StarSuite flaw  eiverson@... | 09/21/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here