Openoffice Installs Insecure Version Of Java


Recommended Posts

5 February 2009, 14:38

OpenOffice installs insecure version of Java

In a report by the Washington Post, Brian Krebs points out that the current version of Open Office 3.0.1 installs an outdated and insecure version of Java. OpenOffice, a free open source office suite, by default installs Java 6 Update 7, during suite installation. Update 7, originally released last spring, still contains several un-patched security vulnerabilities that could be exploited by an attacker and was released prior to Sun's inclusion of a feature known as "secure static versioning." The feature is intended to prevent Web sites from invoking even older versions of Java that may be present on the user's system.

It is unknown why OpenOffice still ships with the outdated version of Java 6, considering the current release, Java 6 Update 12, appears to work fine in the office suite. Krebs notes that he has contacted the OpenOffice security team about the issue and is waiting to hear back from them. According to Simon Phipps, chief open source officer at Sun Microsystems, there have been 35 million downloads of OpenOffice since October 2008.

See also:

Heise security: http://www.heise-online.co.uk/security/Ope...a--/news/112570

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...