Star Office 5.1 Buffer Overflow Vulnerabilities

A number of buffer overflow vulnerabilities exist in Star Office 5.1, from Sun Microsystems. While an exact list of all the vulnerabilities present was not made available, a number of them seem to relate to URL code, in both HTML and Star Office native format. By supplying either html or a native document with a long URL, it is possible to cause Star Office to buffer overflow, due to an unchecked strcpy() taking place.

In order for this attack to be successful, a user would have to download either an html or Star Office document (although other formats, such as Word might work as well), and load it in to Star Office. The attacker would have embedded shellcode, in the form of a long URL, in to the document, and would be able to execute code as the user running Star Office.


