iDefense Security Advisory 06.10.08 – Remote exploitation of an integer overflow vulnerability in OpenOffice, as included in various vendors’ operating system distributions, allows attackers to execute arbitrary code with the privileges of the logged-in user. The vulnerability exists due to the rtl_allocateMemory() function rounding up allocation requests to be aligned on an 8 byte boundary without checking if this rounding results in an integer overflow condition. iDefense has confirmed the existence of this vulnerability in OpenOffice version 2.4. Previous versions may also be affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/67121/06.10.08-1.txt
Source: https://packetstormsecurity.com/files/67121/iDEFENSE-Security-Advisory-2008-06-10.1.html

