Bug 821726 (CVE-2012-1149)

Summary: CVE-2012-1149 openoffice.org, libreoffice: Integer overflows, leading to heap-buffer overflows in JPEG, PNG and BMP reader implementations
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: caolanm, mjc, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-08-24 15:54:13 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 822216, 822966, 822967, 822969, 822970    
Bug Blocks: 821911    
Attachments:
Description Flags
RHEL-5 backport none

Description Jan Lieskovsky 2012-05-15 12:56:38 UTC
Multiple integer overflows, leading to heap-based buffer overflows were found in the way JPEG, PNG and BMP image file reader implementations of the LibreOffice and OpenOffice.org application suites performed scanning / loading of JPEG, PNG and BMP image files. A remote attacker could provide a specially-crafted JPEG, PNG or BMP image file, which once opened by a victim in an application from the LibreOffice or OpenOffice.org application suite would lead to that application crash, or, potentially arbitrary code execution with the privileges of the user running the application.

Upstream patches:
[1] http://cgit.freedesktop.org/libreoffice/core/commit/?id=fe40da4cb640819d869d1c925869bc87ede9bbfe
[2] http://cgit.freedesktop.org/libreoffice/core/commit/?id=88e0fa4aa3bea9ffeee372b6a428ca62cee41203
[3] http://cgit.freedesktop.org/libreoffice/core/commit/?id=9ff94ae0fa947c5fd6a31fbc38421f60eb5e1fba

Comment 2 Jan Lieskovsky 2012-05-15 13:01:09 UTC
This issue affects the versions of the openoffice.org package, as shipped with Red Hat Enterprise Linux 5 and 6.

--

This issue affects the versions of the libreoffice package, as shipped with Fedora release of 15 and 16.

Comment 3 Jan Lieskovsky 2012-05-15 13:41:13 UTC
Acknowledgements:

Upstream acknowledges Tielei Wang via Secunia SVCRP as the original reporter of this issue.

Comment 4 Jan Lieskovsky 2012-05-15 13:42:45 UTC
Preliminary embargo date, proposed by upstream, is tomorrow, Wednesday, 16-th May 2012 at 14:00 UTC time.

Comment 5 Caolan McNamara 2012-05-16 08:14:53 UTC
Created attachment 584889 [details]
RHEL-5 backport

Comment 6 Caolan McNamara 2012-05-16 13:54:30 UTC
(In reply to comment #5)
> Created attachment 584889 [details]
> RHEL-5 backport

applies and works for RHEL-6 too

Comment 7 Jan Lieskovsky 2012-05-16 15:58:00 UTC
LibreOffice upstream advisory:
[4] http://www.libreoffice.org/advisories/cve-2012-1149/

OpenOffice.org upstream advisory:
[5] http://www.openoffice.org/security/cves/CVE-2012-1149.html

Comment 8 Jan Lieskovsky 2012-05-16 16:24:26 UTC
Created libreoffice tracking bugs for this issue

Affects: fedora-all [bug 822216]

Comment 12 errata-xmlrpc 2012-06-05 01:11:06 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5
  Red Hat Enterprise Linux 6

Via RHSA-2012:0705 https://rhn.redhat.com/errata/RHSA-2012-0705.html