Referenced CVEs:
CVE-2009-0200, CVE-2009-0201, CVE-2009-2139
Description:
===========================================================Ubuntu Security Notice USN-840-1 October 01, 2009openoffice.org vulnerabilitiesCVE-2009-0200, CVE-2009-0201, CVE-2009-2139===========================================================A security issue affects the following Ubuntu releases:Ubuntu 8.04 LTSUbuntu 8.10Ubuntu 9.04This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 8.04 LTS: openoffice.org-core 1:2.4.1-1ubuntu2.2Ubuntu 8.10: openoffice.org-core 1:2.4.1-11ubuntu2.2Ubuntu 9.04: openoffice.org-core 1:3.0.1-9ubuntu3.1After a standard system upgrade you need to restart OpenOffice.org toeffect the necessary changes.Details follow:Dyon Balding discovered flaws in the way OpenOffice.org handled tables. Ifa user were tricked into opening a specially crafted Word document, aremote attacker might be able to execute arbitrary code with userprivileges. (CVE-2009-0200, CVE-2009-0201)A memory overflow flaw was discovered in OpenOffice.org's handling of EMFfiles. If a user were tricked into opening a specially crafted document, aremote attacker might be able to execute arbitrary code with userprivileges. (CVE-2009-2139)
More...