Bug 154540

Summary: CAN-2005-0941 openoffice.org heap overflow
Product: Red Hat Enterprise Linux 4 Reporter: Josh Bressers <bressers>
Component: openoffice.orgAssignee: Dan Williams <dcbw>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: medium    
Version: 4.0CC: caolanm
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=important,public=20050412,source=bugtraq,reported=20050412
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2005-04-25 20:35:56 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
exploit doc for this vuln none

Description Josh Bressers 2005-04-12 15:20:57 UTC
A heap overflow was reported in openoffice.org
http://www.securityfocus.com/archive/1/395516/2005-04-08/2005-04-14/0


The patch is located here:
http://util.openoffice.org/source/browse/util/sot/source/sdstor/stgole.cxx?r1=1.4&r2=1.4.166.1

The upstream bug with a demo exploit is here:
http://www.openoffice.org/issues/show_bug.cgi?id=46388

Comment 1 Josh Bressers 2005-04-12 15:21:45 UTC
This issue also affects RHEL3

Comment 2 Josh Bressers 2005-04-12 15:45:43 UTC
This issue is going to be covered by RHSA-2005:375

Comment 3 Dan Williams 2005-04-14 14:49:07 UTC
Created attachment 113151 [details]
exploit doc for this vuln

Comment 4 Dan Williams 2005-04-14 16:37:50 UTC
packages attached to RHSA-2005:375 and passed rpmdiff.  Awaiting QA.

Comment 5 Josh Bressers 2005-04-25 20:35:56 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2005-375.html