Bug 154540 - CAN-2005-0941 openoffice.org heap overflow
Summary: CAN-2005-0941 openoffice.org heap overflow
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 4
Classification: Red Hat
Component: openoffice.org
Version: 4.0
Hardware: All
OS: Linux
medium
high
Target Milestone: ---
: ---
Assignee: Dan Williams
QA Contact:
URL:
Whiteboard: impact=important,public=20050412,sour...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2005-04-12 15:20 UTC by Josh Bressers
Modified: 2007-11-30 22:07 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2005-04-25 20:35:56 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)
exploit doc for this vuln (31.50 KB, application/msword)
2005-04-14 14:49 UTC, Dan Williams
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2005:375 0 high SHIPPED_LIVE Important: openoffice.org security update 2005-04-25 04:00:00 UTC

Description Josh Bressers 2005-04-12 15:20:57 UTC
A heap overflow was reported in openoffice.org
http://www.securityfocus.com/archive/1/395516/2005-04-08/2005-04-14/0


The patch is located here:
http://util.openoffice.org/source/browse/util/sot/source/sdstor/stgole.cxx?r1=1.4&r2=1.4.166.1

The upstream bug with a demo exploit is here:
http://www.openoffice.org/issues/show_bug.cgi?id=46388

Comment 1 Josh Bressers 2005-04-12 15:21:45 UTC
This issue also affects RHEL3

Comment 2 Josh Bressers 2005-04-12 15:45:43 UTC
This issue is going to be covered by RHSA-2005:375

Comment 3 Dan Williams 2005-04-14 14:49:07 UTC
Created attachment 113151 [details]
exploit doc for this vuln

Comment 4 Dan Williams 2005-04-14 16:37:50 UTC
packages attached to RHSA-2005:375 and passed rpmdiff.  Awaiting QA.

Comment 5 Josh Bressers 2005-04-25 20:35:56 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2005-375.html



Note You need to log in before you can comment on or make changes to this bug.