|
|
CVE-2007-4575Potential arbitrary code execution vulnerability in 3rd party module (HSQLDB)
1. ImpactA security vulnerability in HSQLDB, the default database engine shipped with OpenOffice.org 2 (all versions), may allow attackers to execute arbitrary static Java code, by manipulating database documents to be opened by a user. 2. Affected releasesAll versions prior to OpenOffice.org 2.3.1 3. SymptomsThere are no predictable symptoms that would indicate this issue has occurred 4. Relief/WorkaroundThere is no workaround. See "Resolution" below. 5. ResolutionThis issue is addressed in the following releases: HSQLDB 1.8.0.9 / OpenOffice.org 2.3.1 |


