Upstream information
Description
Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a .. (dot dot) in an entry in (1) an XSLT JAR filter description file, (2) an Extension (aka OXT) file, or unspecified other (3) JAR or (4) ZIP files.NVD CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Novell Bugzilla entry: 667421, 683605 SUSE Security Advisories:- SUSE-SR:2011:007, published Tue, 19 Apr 2011 12:00:00 +0000
- openSUSE-SU-2011:0336-1, published Fri, 15 Apr 2011 22:01:47 +0200 (CEST)
- openSUSE-SU-2011:0337-1, published Fri, 15 Apr 2011 22:01:51 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Desktop 10 SP3 for x86 |
| sles10-sp3.x86-64 sles10-sp3-debuginfo.x86-64 sles10-sp3-debuginfo.x86 sles10-sp3.x86 sled10-sp3.x86-64 sle10-sp3-sdk.x86-64 sled10-sp3.x86 sle10-sp3-sdk.x86 ZYPP Patch Nr: 7365 |
| SUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64T |
| sles10-sp3.x86-64 sles10-sp3-debuginfo.x86-64 sles10-sp3-debuginfo.x86 sles10-sp3.x86 sled10-sp3.x86-64 sle10-sp3-sdk.x86-64 sled10-sp3.x86 sle10-sp3-sdk.x86 ZYPP Patch Nr: 7365 |
| SUSE Linux Enterprise Server 10 SP3 DEBUGINFO |
| sles10-sp3.x86-64 sles10-sp3-debuginfo.x86-64 sles10-sp3-debuginfo.x86 sles10-sp3.x86 sled10-sp3.x86-64 sle10-sp3-sdk.x86-64 sled10-sp3.x86 sle10-sp3-sdk.x86 ZYPP Patch Nr: 7365 |
| SUSE Linux Enterprise Server 10 SP3 SUSE Linux Enterprise Server for SAP 10 SP3 |
| sles10-sp3.x86-64 sles10-sp3-debuginfo.x86-64 sles10-sp3-debuginfo.x86 sles10-sp3.x86 sled10-sp3.x86-64 sle10-sp3-sdk.x86-64 sled10-sp3.x86 sle10-sp3-sdk.x86 ZYPP Patch Nr: 7365 |
| SUSE Linux Enterprise SDK 10 SP3 |
| sles10-sp3.x86-64 sles10-sp3-debuginfo.x86-64 sles10-sp3-debuginfo.x86 sles10-sp3.x86 sled10-sp3.x86-64 sle10-sp3-sdk.x86-64 sled10-sp3.x86 sle10-sp3-sdk.x86 ZYPP Patch Nr: 7365 |
| SUSE Linux Enterprise SDK 10 SP3 |
| sles10-sp3.x86-64 sles10-sp3-debuginfo.x86-64 sles10-sp3-debuginfo.x86 sles10-sp3.x86 sled10-sp3.x86-64 sle10-sp3-sdk.x86-64 sled10-sp3.x86 sle10-sp3-sdk.x86 ZYPP Patch Nr: 7365 |
| openSUSE 11.2 |
| |
| openSUSE 11.2 |
| |
| openSUSE 11.3 |
| |
| openSUSE 11.3 |
| |
| SLE 11 SP1 DEBUGINFO |
| sle11-sp1-sdk.x86 sle11-sp1-sdk.x86-64 sled11-sp1.x86 sled11-sp1.x86-64 SAT Patch Nr: 4082 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 |
| sle11-sp1-sdk.x86 sle11-sp1-sdk.x86-64 sled11-sp1.x86 sled11-sp1.x86-64 SAT Patch Nr: 4082 |
| SUSE Linux Enterprise Desktop 11 SP1 |
| sle11-sp1-sdk.x86 sle11-sp1-sdk.x86-64 sled11-sp1.x86 sled11-sp1.x86-64 SAT Patch Nr: 4082 |
