FYI…

- http://isc.sans.org/diary.php?storyid=1454
Last Updated: 2006-06-30 02:14:13 UTC
"OpenOffice.org released a security bulletin* today that addresses three security issues in the OpenOffice.org software which were discovered during an internal code audit. The vulnerabilities affect both the older 1.1.x and the newer 2.0.x releases. OpenOffice.org has released version 2.0.3** which resolves the issues. A patch for version 1.1.5 will be available soon. Without the patch, one of the issues has a possible workaround to alleviate the issue; the other two do not. OpenOffice.org has additional security notes* on their site that address the three specific issues…"

* http://www.openoffice.org/security/bulletin-20060629.html

** http://download.openoffice.org/index.html
(92.3 MB)

EDIT/ADD:
- http://secunia.com/advisories/20867/
Release Date: 2006-06-30
Critical: Moderately critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Software: OpenOffice 1.1.x, OpenOffice.org 2.x …
Solution: Update to the fixed version or apply patches when available.
OpenOffice 2.0.x: Update to version 2.0.3.
http://download.openoffice.org/2.0.3/index.html
OpenOffice 1.1.x: A patch for version 1.1.5 will reportedly be released shortly. The vendor recommends disabling Java Applets as a workaround for vulnerability #1…"

:ph34r: