Security Vulnerability in OpenOffice.org's PDF Import extension resulting from 3rd party library XPDF
- Synopsis: A security vulnerability in the 3rd party library XPDF, related to PDF document processing, may lead to arbitrary code execution.
- State: Resolved
A security vulnerability in the 3rd party library XPDF (only used in the PDF import extension), related to PDF document processing, may allow a remote unprivileged user to execute arbitrary code on the system with the privileges of a local user running OpenOffice.org, if the local user opens a crafted PDF document provided by the remote user.
2. Affected releases
- All versions of OpenOffice.org's PDF Import extension prior to version 1.0.4
There are no predictable symptoms that would indicate this issue has occurred.
To workaround the described issue, do not load documents from untrusted sources.
This issue is addressed in the following release: PDF Import Extension 1.0.4