Red Hat Bugzilla – Bug 481311
[fix available] openoffice.org: Word processor crash due the improper recognition of an Unicode char in Type1 fonts [rhel3]
Last modified: 2010-02-18 04:21:12 EST
Description of problem:
The Word processor, as shipped with OpenOffice.org packages crashes
due the improper recognition of an Unicode character in True Type1 fonts
More details from Caolan McNamara:
So this seems to be due to a unicode char 0xFFFF being looked up in an
Type1 font. Later versions of OOo filter out that glyph as a DELETED
glyph and don't ask the font for it, very old OOos like 1.1.5 don't.
Steps to reproduce:
1, wget http://milw0rm.com/sploits/2008-crash.doc.rar
2, unrar x 2008-crash.doc.rar
3, oowriter/ooffice test.doc
The file content displayed with no crash.
Created attachment 329845 [details]
patch to fix
Official Statement from Red Hat (01/23/2009)
This issue can only result in an OpenOffice.org crash, not allowing arbitrary code execution. Red Hat does not consider a crash of a client application such as OpenOffice.org to be a security issue.
Development Management has reviewed and declined this request. You may appeal
this decision by reopening this request.