Bug 1226188 - calibre: vulnerable embedded copy of WOFF
Summary: calibre: vulnerable embedded copy of WOFF
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1226189
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-05-29 07:40 UTC by Martin Prpič
Modified: 2019-09-29 13:33 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2016-06-27 16:02:21 UTC
Embargoed:


Attachments (Terms of Use)

Description Martin Prpič 2015-05-29 07:40:27 UTC
Calibre contains an outdated embedded copy of Mozilla's WOFF code (in src/calibre/utils/fonts/woff/), which is known to have some security issues.

1) https://bugzilla.mozilla.org/show_bug.cgi?id=552216 (aka CVE-2010-1028)

Patch: https://hg.mozilla.org/releases/mozilla-1.9.2/rev/827a6883442f

2) https://bugzilla.mozilla.org/show_bug.cgi?id=522308

Patch: https://hg.mozilla.org/mozilla-central/rev/69eb050f2c0a

Mozilla's newest release does not contain the vulnerable code.

Originally reported at:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=787085

Comment 1 Martin Prpič 2015-05-29 07:40:50 UTC
Created calibre tracking bugs for this issue:

Affects: fedora-all [bug 1226189]

Comment 2 Zbigniew Jędrzejewski-Szmek 2015-05-29 13:13:04 UTC
Is there a shared library that could be used instead? (dnf search doesn't return anything useful.)

Comment 3 Martin Prpič 2015-05-29 13:30:14 UTC
(In reply to Zbigniew Jędrzejewski-Szmek from comment #2)
> Is there a shared library that could be used instead? (dnf search doesn't
> return anything useful.)

I couldn't find anything either. I suppose updating the embedded copy is the way to go. Other than that, you could propose a new package to be added to the repos.

Comment 4 Johannes Römer 2016-06-26 13:27:50 UTC
The WOFF code has been removed from Calibre with version 2.34 (released on August 7, 2015).
https://github.com/kovidgoyal/calibre/commit/f862513e830d27eab7613d2aaa6104d7a9c55d5a

Fedora already packages newer versions of Calibre, so this should not be an issue any more.

Comment 5 Kevin Fenzi 2016-06-27 16:02:21 UTC
Yep. this looks like it's no longer an issue...


Note You need to log in before you can comment on or make changes to this bug.