Bug 217957

Summary: CVE-2006-4514 libgsf heap overflow
Product: [Fedora] Fedora Reporter: Josh Bressers <bressers>
Component: libgsfAssignee: Caolan McNamara <caolanm>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 6Keywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: source=idefense,reported=20061130,public=20061130,impact=moderate
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-12-07 19:11:09 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Josh Bressers 2006-11-30 21:40:22 UTC
+++ This bug was initially created as a clone of Bug #217949 +++

infamous41md discovered a heap overflow in libgsf.  When a specially crafted OLE
document is opened, it can overflow a buffer possibly leading to arbitrary code
execution.

-- Additional comment from bressers on 2006-11-30 16:08 EST --
Created an attachment (id=142527)
Patch extracted from upstream CVS


This flaw should also affect FC5

Comment 1 Caolan McNamara 2006-12-01 09:35:57 UTC
The FC-6 release already has this fix included, FC-5 update provided

Comment 4 Caolan McNamara 2006-12-07 09:11:14 UTC
rats, cvs lead me astray,
FC-6: libgsf-1.14.1-7

Comment 5 Fedora Update System 2006-12-07 18:09:50 UTC
libgsf-1.14.1-7 has been pushed for fc6, which should resolve this issue.  If these problems are still present in this version, then please make note of it in this bug report.