Bug 725668 (CVE-2011-2713)

Summary: CVE-2011-2713 openoffice.org: Out-of-bounds read in DOC sprm parser
Product: [Other] Security Response Reporter: Huzaifa S. Sidhpurwala <huzaifas>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: caolanm, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: public=20111004,reported=20110726,source=redhat,impact=moderate,cvss2=4.3/AV:N/AC:M/Au:N/C:N/I:N/A:P,fedora-all/libreoffice=affected,rhel-6/openoffice.org=affected,rhel-4/openoffice.org=affected,rhel-5/openoffice.org=affected,cwe=CWE-125[auto]
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-10-05 06:41:16 EDT Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
Bug Depends On:    
Bug Blocks: 725683    
Description Flags
combined backport to OpenOffice.org 3.2.1 none

Description Huzaifa S. Sidhpurwala 2011-07-26 04:48:45 EDT
 A heap-based buffer out-ouf-bounds read was found in the way OpenOffice.org imported certain Microsoft Word Binary File Format (.DOC) file.If a user opened a specially-crafted DOC file in OpenOffice.org suite tool (oowriter), it could lead to denial of service (oowriter executable crash), or possibly, execute arbitrary code with the privileges of the user running OpenOffice.org Writer.

This has been assigned CVE-2011-2713.
Comment 2 Huzaifa S. Sidhpurwala 2011-07-26 04:53:50 EDT
Created attachment 515212 [details]
Comment 3 Huzaifa S. Sidhpurwala 2011-07-26 04:54:30 EDT
Created attachment 515213 [details]
Comment 4 Huzaifa S. Sidhpurwala 2011-07-26 04:54:51 EDT
Created attachment 515214 [details]
Comment 5 Huzaifa S. Sidhpurwala 2011-07-26 04:55:23 EDT
Created attachment 515215 [details]
Comment 6 Huzaifa S. Sidhpurwala 2011-07-26 04:55:47 EDT
Created attachment 515216 [details]
Comment 12 Caolan McNamara 2011-09-16 12:00:13 EDT
Created attachment 523579 [details]
combined backport to OpenOffice.org 3.2.1
Comment 13 Huzaifa S. Sidhpurwala 2011-10-05 06:38:42 EDT
This is public via:
Comment 14 Huzaifa S. Sidhpurwala 2011-10-05 06:40:46 EDT
It initially appeared that this flaw may be exploitable similar to CVE-2010-3452, where an OOB Read caused Arbitrary Code Execution. However in the case of this particular flaw, the junk data read is just parsed into an internal representation of properties and the maximum harm this should cause in application crash (Denial Of Service). 

- Reported to securityteam@openoffice.org on 25-July-2011
- Recieved a reply (with tdf-security@lists.documentfoundation.org copied) on the same date 
- Release date changed with a few delays in between
- Release on 5-Oct-2011


This issue results in an OOB read which is not exploitable for arbitrary code execution and can simply cause a crash. We do not consider this as a security issue.
Comment 15 Murray McAllister 2012-10-03 00:20:13 EDT

This issue was discovered by Huzaifa Sidhpurwala of the Red Hat Security Response Team.