20060703 Monday July 03, 2006

About the latest StarOffice and OpenOffice.org security vulnerabilities

By now you might have seen Sun's and OpenOffice.org's security alerts.

I just wanted to tell you that this is not “stardust” or “starbugs”.
These two where not able to bypass any security checks.

But the appearance of 'intended' viruses for StarOffice and OpenOffice.org caused some Sun security specialists to do deeper security audits.

In the end, they found the two issues with Macros and with Java Applets.

The way how they tricked StarOffice with macros was really interesting for us...

An other thing that we have learned from stardust and starbugs:

The security holes are fixed now, but people might still execute unknown macros, because they ignore all warnings.

I hope AV vendors will implement better support for ODF files soon, so these people are better protected, at least against known malicious macros.

Posted by Malte Timmermann ( Jul 03 2006, 02:07:47 PM CEST ) Permalink Comments [1]

 

Trackback URL: http://blogs.sun.com/malte/entry/about_the_latest_staroffice_and
Comments:

PHP have a safe mode that allow to blacklist some functions or limit where functions can add/edit/remove files : http://www.php.net/manual/en/features.safe-mode.php IMHO OpenOffice.org could use something like this. In a default configuration, OO is set to a high security level. In this high security level, some functions are blacklisted or restricted ( external command execution, filesystem access, ... ). If the user want to use them, he will have to authorized individually the function, or lower his security level. It's somewhat like modern application firewalls. In high security level, you have to explicitely allow an application to go to internet ( or use network ressources ). You can also lower your security level and be in an automatic mode ( or semi-automatic mode ).

Posted by FACORAT Fabrice on July 03, 2006 at 06:24 PM CEST #

Post a Comment:

Name:
E-Mail:
URL:

Your Comment:

HTML Syntax: NOT allowed

Archives
Links

New Entry   Logout