System News
   
News about Solaris and Sun Microsystems

Free 2 Week Trial!


April 21, 2008
Article #19748
Volume 122, Issue 4
Section: Free and Open Source Software

 

Version 2.4 of OpenOffice.org...fixed a number of security vulnerabilities. Users are advised to upgrade to afford themselves of this additional protection.
 


 

Latest OpenOffice.org Release - Version 2.4
Several Security Vulnerabilities Repaired, New Features Added

Version 2.4 of OpenOffice.org, which is now available for immediate download, fixed a number of security vulnerabilities. Users are advised to upgrade to afford themselves of this additional protection. The new features of Version 2.4 are cited in the following paragraphs. Because not all platforms and languages (localizations) are ready yet, users are encouraged to check back shortly and also check with their Native Language community.

Fixed in OpenOffice.org 2.4 are the following vulnerabilities:

  • CVE-2007-4770/4771: Manipulated ODF text documents containing XForms can lead to heap overflows and arbitrary code execution
  • CVE-2007-5745/5747: Manipulated Quattro Pro files can lead to heap overflows and arbitrary code execution
  • CVE-2007-5746: Manipulated EMF files can lead to heap overflows and arbitrary code execution
  • CVE-2008-0320: Manipulated OLE files can lead to heap overflows and arbitrary code execution

Full details of the vulnerabilities fixed are available in a security bulletin.

General information concerning OpenOffice.org Version 2.4 is as follows:

  • Connect to WebDAV servers via HTTPS
  • Custom icons for toolbars are imported
  • Control password-storing with a master password
  • Warning if document is from a newer ODF
  • PDF documents: relative links, document references, PDF/A-1 (ISO 19005-1) supported, and cross-document link behavior options
  • Mac OS X: Quicktime support for movies and sound / use the built in spell checker
  • Print dialog improvements in usability
  • Edit boxes: warning at limit of characters
  • DejaVu font is now default instead of BitStream Vera

Information on the components of OpenOffice.org Version 2.4:

Base / DBA

  • Improved rendering of numeric(n) data from JDBC and Oracle
  • Easier choice of table name in "Copy table"
  • Editing of views in HSQLDB
  • Query designer for all properties which allow SQL command
  • Query designer in SQL view
  • Relation design accessible for MySQL databases
  • Setting to check for required fields on forms
  • Support for Access 2007 (.accdb files)

Calc

  • Convert text to columns: with this feature CSV data inside cells can be transformed into columns directly
  • Columns and rows in spreadsheet can be moved with drag and drop
  • Enter key returns to the column where the input started, one row below
  • Formula input: "+" and "-" can also be used to start
  • Individual zoom level per sheet
  • AutoFilter: choices clearer grouped and based on result of filtering in other columns
  • DataPilot: Manual Sorting / Double-click in DataPilot cell provides calculation data of that cell
  • Performance improvement with functions VLOOKUP and MATCH
  • Print dialog for Calc easier to use
  • PageUp and PageDown keys work in print preview
  • Sheet names in cell-hyperlinks: renamed properly

Chart

  • Regression curves: show equations and R² value
  • Reverse axes possible
  • Bars on different axes displayed next to each other
  • Data labels: Number format
  • Data point label: display both value and percentage
  • Data label: display each part in a separate line
  • Data labels: more flexible placement of labels
  • Labels on pie segments: avoiding overlapping
  • Data point label: can be removed with delete key

Draw

  • Navigation (tab) order of page objects
  • PDF export: page names as bookmark
  • Reduce complexity: no longer necessary display options removed

Impress

  • Navigation (tab) order of page objects
  • Thrilling 3D effects in slide transitions
  • Export slide names as PDF bookmarks
  • Easier to insert background picture

Writer

  • Selecting rectangular region of text
  • Find and Replace: backward references in regular expressions
  • Spell checking: easier selecting of the language
  • Insert&Insert Object toolbar redesign - Writer
  • Printing of hidden text can be turned on
  • Printing text place holders can be turned off
  • Shortcuts added for paragraph style Heading 4, Heading 5 and Textbody
  • Ctrl-click behaviour for hyperlinks can be changed
  • Custom document properties: Text fields and UI support

Extensions/ programmability / API

  • Extensible Help System for extensions
  • Extensions can have a separate display name
  • Extensions: support of web based update
  • Extensions: additional information about the publisher and release notes
  • Extensions: check for updates
  • Dialogs can have a wallpaper set
  • Transparent background for controls
  • Remote control presentations via API
  • API: get selected table(s) or query(s) in the main Base window

For more updates on this release and detailed specifics, visit OpenOffice.org. [...read more...]

fullsource

Keywords:
Other articles in the Free and Open Source Software section of Volume 122, Issue 4:

See all archived articles in the Free and Open Source Software section.


From the latest issue:




 


Customized news reports about Sun Microsystems. Just the news you need, none of what you don't.
50,000+ Members. 20,000+ Articles Published since 1998.