http://mcpmag.com/columns/article.asp?EditorialsID=1430
|
Quote:
|
|
Three vulnerabilities have been reported in OpenOffice. The first could allow a malicious Java applet, embedded in an OpenOffice document, to bypass the Java sandbox restrictions. The second involves macros embedded in documents, which could allow for basic code of the attacker's choice to run. The third involves improper handling of XML document elements and could allow arbitrary code of the attacker's choice to run.
|
This is a bit of MS fighting back, but the priniple is reasonable. The threats are relatively minimal, as it is a pretty slight chance of getting affected by these... but nothing is perfect and obscurity is the best defence.