Bug 1165737 (CVE-2014-9093)

Summary: CVE-2014-9093 libreoffice: crash importing malformed .rtf
Product: [Other] Security Response Reporter: Vasyl Kaigorodov <vkaigoro>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: caolanm, dtardon, erack, jgrulich, sbergman
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: libreoffice 4.4.0, libreoffice 4.3.5 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-08 02:36:25 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 1165740    
Bug Blocks: 1165739    

Description Vasyl Kaigorodov 2014-11-19 14:54:24 UTC
A crash was reported [1] in libreoffice that potentially might lead to code execution.
Upstream patch is at [2].

[1]: https://bugs.freedesktop.org/show_bug.cgi?id=86449
[2]: http://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-4-3

Comment 1 Vasyl Kaigorodov 2014-11-19 14:59:19 UTC
Created libreoffice tracking bugs for this issue:

Affects: fedora-all [bug 1165740]

Comment 2 Martin Prpič 2014-11-26 10:22:51 UTC
MITRE assigned CVE-2014-9093 to this issue:

http://seclists.org/oss-sec/2014/q4/805