Risk: Medium
OpenOffice version 2.0.4 and earlier versions are vulnerable to maliciously crafted TIFF files, which can be delivered as an email attachment, published on a website or shared using peer-to-peer software.
The bug allows an attacker to use malformed TIFF images to run malicious code on a victim's computer for the purpose of spreading the code, such as a Trojan.
Users are advised to update to version 2.3 or to apply the vendor patch.