Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1425844 - (CVE-2017-3157) CVE-2017-3157 libreoffice: Arbitrary file disclosure in Calc and Writer
CVE-2017-3157 libreoffice: Arbitrary file disclosure in Calc and Writer
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20170222,repor...
: Reopened, Security
Depends On: 1435532 1435533 1435534 1435535
Blocks: 1425845
  Show dependency treegraph
 
Reported: 2017-02-22 10:14 EST by Andrej Nemec
Modified: 2017-05-10 06:49 EDT (History)
7 users (show)

See Also:
Fixed In Version: libreoffice 5.1.6, libreoffice 5.2.5, libreoffice 5.3.0
Doc Type: If docs needed, set a value
Doc Text:
It was found that LibreOffice disclosed contents of a file specified in an embedded object's preview. An attacker could potentially use this flaw to expose details of a system running LibreOffice as an online service via a crafted document.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2017-04-18 01:23:03 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:0914 normal SHIPPED_LIVE Moderate: libreoffice security and bug fix update 2017-04-12 12:26:10 EDT
Red Hat Product Errata RHSA-2017:0979 normal SHIPPED_LIVE Moderate: libreoffice security update 2017-04-18 05:06:07 EDT

  None (edit)
Description Andrej Nemec 2017-02-22 10:14:23 EST
Embedded Objects in writer and calc can contain previews of their content. A document can be crafted which contains an embedded object that is a link to an existing file on the targets system. On load the preview of the embedded object will be updated to reflect the content of the file on the target system. In the case of LibreOffice used as an online service that preview of data on the target system could be used to expose details of the environment LibreOffice is running in. In the case of LibreOffice as a standard desktop application, the preview could be concealed in hidden sections and retrieved by the attacker if the document is saved and returned to sender.

External References:

http://www.libreoffice.org/about-us/security/advisories/cve-2017-3157/
Comment 7 errata-xmlrpc 2017-04-12 08:35:40 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2017:0914 https://access.redhat.com/errata/RHSA-2017:0914
Comment 8 errata-xmlrpc 2017-04-18 01:06:25 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2017:0979 https://access.redhat.com/errata/RHSA-2017:0979
Comment 9 richard rigby 2017-05-10 06:49:34 EDT
this update appears to cause issues on libreoffice 4.3 / el6.

for example:

  * create a writer document
  * insert a formula
  * save and close the document
  * open the saved document in writer
  * edit the formula
  * the formula preview is replaced by 'object 1'.

i also tested impress, which also seems to have issues, but just doesn't display anything, rather than 'object 1'.

the formulas do seem to remain editable, though while testing, i think i managed to get to a state where this was not the case ...

things seem to work o.k. on libreoffice 5 / el7.

thanks,

richard

Note You need to log in before you can comment on or make changes to this bug.