Risk: High
A flaw reported in OpenOffice may be exploited by malicious people in order to compromise a user's system.
The flaw resides in the default database engine, HSQLDB, supplied with version 2 of the application. The flaw may be expolited by a specially crafted SQL query contained within the database, which may allow an attacker to execute arbitrary static JavaScript.
OpenOffice.org 2.3.1 has been released and users are recommended to upgrade to this version.