CVE-2008-3437
01.08.2008, 14:41
OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
Vendor | Product | Version |
---|---|---|
openoffice | openoffice.org | 1.1.5 |
openoffice | openoffice.org | 2.0 |
openoffice | openoffice.org | 2.0.2 |
openoffice | openoffice.org | 2.0.3 |
openoffice | openoffice.org | 2.0.4 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References