Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 500993 - (CVE-2009-0200) CVE-2009-0200 OpenOffice.org Word document Integer Underflow
CVE-2009-0200 OpenOffice.org Word document Integer Underflow
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,source=openoffice.or...
: Security
Depends On: 519163 519164 519165 519166 519167 519169 519170
Blocks:
  Show dependency treegraph
 
Reported: 2009-05-15 08:13 EDT by Josh Bressers
Modified: 2016-03-04 07:15 EST (History)
7 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2009-09-04 06:36:48 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
my proposed patch (2.29 KB, patch)
2009-05-15 08:31 EDT, Caolan McNamara
no flags Details | Diff
final patch (same as the originaly really) (3.64 KB, patch)
2009-08-21 08:09 EDT, Caolan McNamara
no flags Details | Diff


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2009:1426 normal SHIPPED_LIVE Important: openoffice.org security update 2009-09-04 06:24:15 EDT

  None (edit)
Description Josh Bressers 2009-05-15 08:13:33 EDT
Dyon Balding of Secunia Research has reported a flaw in OpenOffice.org's MS Word handling code. When parsing the sprmTDelete record an integer underflow can be triggered that could result in a heap-based buffer overflow.
Comment 3 Caolan McNamara 2009-05-15 08:31:08 EDT
Created attachment 344137 [details]
my proposed patch
Comment 9 Caolan McNamara 2009-08-21 08:09:12 EDT
Created attachment 358230 [details]
final patch (same as the originaly really)
Comment 13 Tomas Hoger 2009-08-31 08:55:30 EDT
New upstream OpenOffice.org release 3.1.1 is out including the fix, details of the flaw remain non-public until Sep11.

http://www.openoffice.org/servlets/ReadMsg?list=announce&msgNo=398
Comment 14 Vincent Danen 2009-09-01 10:27:01 EDT
This is public now: http://secunia.com/advisories/35036/
Comment 15 Fedora Update System 2009-09-02 03:42:27 EDT
openoffice.org-3.0.1-15.5.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/openoffice.org-3.0.1-15.5.fc10
Comment 16 Fedora Update System 2009-09-03 04:00:56 EDT
openoffice.org-3.0.1-15.6.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/openoffice.org-3.0.1-15.6.fc10
Comment 18 Fedora Update System 2009-09-03 23:59:47 EDT
openoffice.org-3.0.1-15.6.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 19 errata-xmlrpc 2009-09-04 06:24:28 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 3
  Red Hat Enterprise Linux 4
  Red Hat Enterprise Linux 5

Via RHSA-2009:1426 https://rhn.redhat.com/errata/RHSA-2009-1426.html
Comment 20 Tomas Hoger 2009-09-04 06:36:48 EDT
F11 is already updated to fixed upstream version 3.1.1.
Comment 21 Tomas Hoger 2009-09-07 15:05:55 EDT
OpenOffice.org Security Bulletin:

http://www.openoffice.org/security/cves/CVE-2009-0200-0201.html

Fixed upstream in upstream versions 3.1.1 and 2.4.3.
Comment 22 Kevin 2009-12-09 09:54:53 EST
FYI: Downgrade conflict detected. I already have 3.1.1 installed. Update service is reporting I need a security fix of openoffice.org-ure-1:3.0.1-15.6.fc10(i386) but I already have openoffice.org-ure-1.5.1-9420.i586.

I don't believe your UNO runtime environment bug fix should be reported as necessary when a later (but non-fedora supplied) version of OOo is installed.
Comment 23 Caolan McNamara 2009-12-09 10:09:58 EST
You have a package called "openoffice.org-ure" from (effectively) a different repository installed on your fedora. Conflicting packages with the same names is unfortunate but neither new nor fully under our control. If you want to mix different repositories which contain conflicting packages using the same name  then you need to disable the packages from the fedora repository, e.g. see man yum.conf and exclude. This is not specific to this or any update.
Comment 24 Kevin 2009-12-09 10:27:36 EST
>>Conflicting packages with the same names is unfortunate but neither new nor fully under our control

My apologies. I thought the version of the package would be checked if already detected as installed on the target before a update would be flagged as necessary. I will do as you suggest, thanks for the info.

rpm -qa | grep "openoffice.org"
openoffice.org3-draw-3.1.1-9420.i586
openoffice.org3-math-3.1.1-9420.i586
openoffice.org3-calc-3.1.1-9420.i586
openoffice.org3-dict-fr-3.1.1-9420.i586
openoffice.org3-impress-3.1.1-9420.i586
openoffice.org-ure-1.5.1-9420.i586
openoffice.org3-3.1.1-9420.i586
openoffice.org3-dict-en-3.1.1-9420.i586
openoffice.org3.1-redhat-menus-3.1-9420.noarch
openoffice.org3-base-3.1.1-9420.i586
openoffice.org3-dict-es-3.1.1-9420.i586
openoffice.org3-en-US-3.1.1-9420.i586
openoffice.org3-writer-3.1.1-9420.i586

Note You need to log in before you can comment on or make changes to this bug.