OpenOffice HSQLDB数据库引擎Java代码执行漏洞
OpenOffice捆绑的默认数据库引擎HSQLDB在解析SQL查询时没有正确地强制安全限制,如果用户打开了恶意数据库,并执行了其中所包含的特制SQL查询,就可能导致调用任意静态的Java方式……
Alpha architecture:
| http://security.debian.org/pool/updates/main/o/openoffice.org/libmythes-dev_2.0.4.dfsg.2-7etch4_alpha.deb Size/MD5 checksum: 107120 8e963ff20a4ebdaf16c8357a139dfd33 |
AMD64 architecture:
| http://security.debian.org/pool/updates/main/o/openoffice.org/libmythes-dev_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 104620 9a5c533b5c83f7afd2e8452275597f03 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 215524 c316b13b8093d4be1709d0a7563ff326 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-base_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 3815418 048aeb9d8076ecc2bafafd2d9a6b1ace http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-calc_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 5409744 0ce5e4ed8bfbae2892d40f2fd6db53db http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-core_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 35708204 689cc403fd954bcd0f0b780edd05e875 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-dbg_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 38172254 9202f9979e5f7f517de7446c78aa0d69 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-dev_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 3756140 d81cc877dc57dea9dbbf99f4e26cb35f http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-draw_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 2544632 5a66877fcc8b1c1a35d32dcc4e42b4fc http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-evolution_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 308014 4adc2bb6bcc486ce1dead88cce92e7ba http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-filter-so52_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 9781700 8e54db5c1916d738fc1046a18fd180be http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gcj_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 5347166 bd0c7a4ebf1f4efe4b132ed0cf8356c7 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gnome_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 295812 e747a57bd3fd5d8eb71b859ab6815207 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gtk_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 403068 3b6e9ba610479a745ce37d9224f1789b http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gtk-gnome_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 213286 afad9de73ac77527f223a12bc163c7be http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-impress_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 857034 8ee9a694032492097fe99855b2225e62 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-kde_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 447840 caf0c4f5244f49761cd00277109b88b1 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-math_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 538226 26eb83a48205c742071e6df4a66449ca http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-officebean_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 252906 e04136219980490604a90e185814cd20 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-qa-tools_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 826792 8aaf2bac665edcc4c653ff70e8a897a4 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-writer_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 6270762 e349bb9f9326b143143277a802160830 http://security.debian.org/pool/updates/main/o/openoffice.org/python-uno_2.0.4.dfsg.2-7etch4_amd64.deb Size/MD5 checksum: 362068 de5856f7704f13569748e53eae326cde |
ARM architecture:
| http://security.debian.org/pool/updates/main/o/openoffice.org/libmythes-dev_2.0.4.dfsg.2-7etch4_arm.deb Size/MD5 checksum: 104896 3bf02c95a3df4c1811eb0217ae8ee4fb |
HP Precision architecture:
| http://security.debian.org/pool/updates/main/o/openoffice.org/libmythes-dev_2.0.4.dfsg.2-7etch4_hppa.deb Size/MD5 checksum: 106394 12cb2296eef63d1f8b0cfd83bfd1ced7 |
Intel IA-32 architecture:
| http://security.debian.org/pool/updates/main/o/openoffice.org/libmythes-dev_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 105182 1ddf8c46c0e2dcffc71be30bd719879f http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 215726 0f25501a3d5cd4c7bbb0a355a2181ac7 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-base_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 3715390 8461efd0bc91658387a5f7856d223388 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-calc_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 5155652 14033d97d152458e93547f5914b6aa8f http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-core_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 34477922 7470c10531c8ec4c88046bfde6b95845 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-dbg_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 36358556 a0df28d56bf5c0e9e7b4333dacdd6768 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-dev_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 3721614 63688677d299657c8cc2021bc8389925 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-draw_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 2484830 13d1eac99916b2d844e595a0e3b87a98 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-evolution_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 302426 cb03d9a7e97c0b0ef8523cb77daa2d0c http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-filter-so52_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 9302166 89b88d17781b2e38b4bd741b4c4255a3 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gcj_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 4368822 d9825cbf765438345cf1f435295fe944 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gnome_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 291608 91fe68b9a5fc91874defd06adc2d2efe http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gtk_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 398090 b089e081ebb4712c398bc65abdf8c396 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gtk-gnome_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 213486 f58ac6b0cded95c1a0b72ade20daafa4 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-impress_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 851702 b95546cfe2c48e3549361b35b958836d http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-kde_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 434734 fe72e98aa560a9aaddba588ec4b97639 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-math_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 522892 db0f48ad21f44a263eb6992552e699f6 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-officebean_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 252860 6188b2d905a558461de8790e9d1c73cf http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-qa-tools_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 824778 7c5abbd7d7618769235c9355d81a4ac3 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-writer_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 6095718 a38d9cf2fa865398df1ec22bf1058fdc http://security.debian.org/pool/updates/main/o/openoffice.org/python-uno_2.0.4.dfsg.2-7etch4_i386.deb Size/MD5 checksum: 357740 ec14129f1534b799a3772508f6008d41 |
Intel IA-64 architecture:
| http://security.debian.org/pool/updates/main/o/openoffice.org/libmythes-dev_2.0.4.dfsg.2-7etch4_ia64.deb Size/MD5 checksum: 105170 ee22bf781f152dc758c7ab13938d5426 |
Big endian MIPS architecture:
| http://security.debian.org/pool/updates/main/o/openoffice.org/libmythes-dev_2.0.4.dfsg.2-7etch4_mips.deb Size/MD5 checksum: 103672 730d85d75c3cf6c5d4c4ee51e65c6177 |
Little endian MIPS architecture:
| http://security.debian.org/pool/updates/main/o/openoffice.org/libmythes-dev_2.0.4.dfsg.2-7etch4_mipsel.deb Size/MD5 checksum: 103736 305e8d3184d1846fa7b87c4fba86ddb1 |
PowerPC architecture:
| http://security.debian.org/pool/updates/main/o/openoffice.org/libmythes-dev_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 105290 720b503b4c18d44193088aa6fcb30882 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 217202 d1e8f29b984d4b464d589bb874feab4d http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-base_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 3891380 6eec53a6433092f7b4d88428dd565bf9 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-calc_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 5291346 fa421b9fb4c5f267770d310d7fed79ec http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-core_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 35847732 7f42d5e557888be5f18dfc70e6c34e4a http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-dbg_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 38479248 9b232580e7b7144f8245bab3f0b3c20e http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-dev_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 3768904 e52a0114fed077ffd3863c3e1727f6a8 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-draw_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 2488740 f2378122ff4682ecd65a102de07ec0a5 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-evolution_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 314066 319e94223675e0ee678ecc7ba2ccb479 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-filter-so52_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 9649486 7984c9cb03d37b38b9354b799abacf58 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gcj_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 5056194 eb15a54b5624a34dc487b918cb0fe2ae http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gnome_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 300964 ced011f9b90b87bd610a73549f44a481 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gtk_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 408176 26a2629e57fc783291cd628b8f4c55aa http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gtk-gnome_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 215024 8535571057b28a04c2a46841c72bd88d http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-impress_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 889280 841950ee58aeeb66f52d6a6eddf62fc1 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-kde_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 450640 6a44ddc61abb45224c0374e462d4209e http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-math_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 519326 54cf2c5b8fe224afcd562bbd97f009bf http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-officebean_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 254060 0b473a2730822a13ce4c418f52833e19 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-qa-tools_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 822412 dce45e844a08f27c42a1ea12dc8a5ce4 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-writer_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 6078974 b090dc1e0081844f2c7a0ac70ef92f08 http://security.debian.org/pool/updates/main/o/openoffice.org/python-uno_2.0.4.dfsg.2-7etch4_powerpc.deb Size/MD5 checksum: 367368 892e32e1e237d315fb78bff156e9f151 |
IBM S/390 architecture:
| http://security.debian.org/pool/updates/main/o/openoffice.org/libmythes-dev_2.0.4.dfsg.2-7etch4_s390.deb Size/MD5 checksum: 105540 808741d0631085491098fe35abc5265b |
Sun Sparc architecture:
| http://security.debian.org/pool/updates/main/o/openoffice.org/libmythes-dev_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 103594 2e4af5329f2778242e7f1289a1197164 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 217062 602d95659af8d9a2f9d9a4c6393ffb82 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-base_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 3919062 d21f72f97bf94e4be09f0386f2184b87 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-calc_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 5323302 702e9a904accc28d00225e5f0931c0ec http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-core_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 35489734 75ae01e0810642586a458caed9d8d4b2 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-dbg_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 36153486 68c65757906b4263af8724a2420e8654 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-dev_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 3604330 e5c2d3e9ea6daeca3414bbc6cbdce6de http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-draw_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 2502484 25aa590e331f65de9a46e2331ec47017 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-evolution_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 314610 4eaf4624ad7aa55704314027ea723e0a http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-filter-so52_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 9659576 94889f34a87ba7fb834e77029a3c3563 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gcj_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 4854098 a0ed03043ede2d8f1c591673380f3991 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gnome_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 293410 e4cae4dc525169c611fb64d4a516f2a5 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gtk_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 395014 26fdb2281fe63f73cd80fff37cd0c9a9 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-gtk-gnome_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 214818 ac9519b13e5e7bd272781343b1e4ba03 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-impress_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 955204 f8482150d08ce22592f8009be1488f94 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-kde_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 448358 37d09cb3a8a3758f8eeb6afe4c0b77a0 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-math_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 509944 dcfa1dfef2dc0c667323a0716446f13a http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-officebean_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 252026 113d0a50cf8874d732b716f127c7635c http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-qa-tools_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 803948 d95f314810ee4d60904c1babdd5709e4 http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-writer_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 6007848 483539c0c19659df2ef8a8bef7972dd7 http://security.debian.org/pool/updates/main/o/openoffice.org/python-uno_2.0.4.dfsg.2-7etch4_sparc.deb Size/MD5 checksum: 365466 016e78926dd07c2c442d817fa1c02a35 |
补丁安装方法:
1. 手工安装补丁包:
首先,使用下面的命令来下载补丁软件:
# wget url (url是补丁下载链接地址)
然后,使用下面的命令来安装补丁:
# dpkg -i file.deb (file是相应的补丁名)
2. 使用apt-get自动安装补丁包:
首先,使用下面的命令更新内部数据库:
# apt-get update
然后,使用下面的命令安装更新软件包:
# apt-get upgrade
RedHat
------
RedHat已经为此发布了一个安全公告(RHSA-2007:1048-01,RHSA-2007:1090-01)以及相应补丁:
RHSA-2007:1048-01:Moderate: openoffice.org, hsqldb security update
链接:https://www.redhat.com/support/errata/RHSA-2007-1048.html
RHSA-2007:1090-01:Moderate: openoffice.org2 security update
链接:https://www.redhat.com/support/errata/RHSA-2007-1090.html
Sun
---
Sun已经为此发布了一个安全公告(Sun-Alert-103141)以及相应补丁:
Sun-Alert-103141:Manipulated Database Documents for StarOffice/StarSuite 8 May Lead to Arbitrary Code Execution
链接:http://sunsolve.sun.com/search/printfriendly.do?assetkey=1-26-103141-1
OpenOffice
----------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
http://download.openoffice.org/2.3.1/index.html?focus=download
- 本文关键词:

