Bug 821726 - (CVE-2012-1149) CVE-2012-1149 openoffice.org, libreoffice: Integer overflows, leading to heap-buffer overflows in JPEG, PNG and BMP reader implementations
CVE-2012-1149 openoffice.org, libreoffice: Integer overflows, leading to heap...
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
: Security
Depends On: 822216 822966 822967 822969 822970
Blocks: 821911
  Show dependency treegraph
Reported: 2012-05-15 08:56 EDT by Jan Lieskovsky
Modified: 2016-03-04 06:58 EST (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2015-08-24 11:54:13 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
RHEL-5 backport (7.48 KB, patch)
2012-05-16 04:14 EDT, Caolan McNamara
no flags Details | Diff

  None (edit)
Description Jan Lieskovsky 2012-05-15 08:56:38 EDT
Multiple integer overflows, leading to heap-based buffer overflows were found in the way JPEG, PNG and BMP image file reader implementations of the LibreOffice and OpenOffice.org application suites performed scanning / loading of JPEG, PNG and BMP image files. A remote attacker could provide a specially-crafted JPEG, PNG or BMP image file, which once opened by a victim in an application from the LibreOffice or OpenOffice.org application suite would lead to that application crash, or, potentially arbitrary code execution with the privileges of the user running the application.

Upstream patches:
[1] http://cgit.freedesktop.org/libreoffice/core/commit/?id=fe40da4cb640819d869d1c925869bc87ede9bbfe
[2] http://cgit.freedesktop.org/libreoffice/core/commit/?id=88e0fa4aa3bea9ffeee372b6a428ca62cee41203
[3] http://cgit.freedesktop.org/libreoffice/core/commit/?id=9ff94ae0fa947c5fd6a31fbc38421f60eb5e1fba
Comment 2 Jan Lieskovsky 2012-05-15 09:01:09 EDT
This issue affects the versions of the openoffice.org package, as shipped with Red Hat Enterprise Linux 5 and 6.


This issue affects the versions of the libreoffice package, as shipped with Fedora release of 15 and 16.
Comment 3 Jan Lieskovsky 2012-05-15 09:41:13 EDT

Upstream acknowledges Tielei Wang via Secunia SVCRP as the original reporter of this issue.
Comment 4 Jan Lieskovsky 2012-05-15 09:42:45 EDT
Preliminary embargo date, proposed by upstream, is tomorrow, Wednesday, 16-th May 2012 at 14:00 UTC time.
Comment 5 Caolan McNamara 2012-05-16 04:14:53 EDT
Created attachment 584889 [details]
RHEL-5 backport
Comment 6 Caolan McNamara 2012-05-16 09:54:30 EDT
(In reply to comment #5)
> Created attachment 584889 [details]
> RHEL-5 backport

applies and works for RHEL-6 too
Comment 7 Jan Lieskovsky 2012-05-16 11:58:00 EDT
LibreOffice upstream advisory:
[4] http://www.libreoffice.org/advisories/cve-2012-1149/

OpenOffice.org upstream advisory:
[5] http://www.openoffice.org/security/cves/CVE-2012-1149.html
Comment 8 Jan Lieskovsky 2012-05-16 12:24:26 EDT
Created libreoffice tracking bugs for this issue

Affects: fedora-all [bug 822216]
Comment 12 errata-xmlrpc 2012-06-04 21:11:06 EDT
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5
  Red Hat Enterprise Linux 6

Via RHSA-2012:0705 https://rhn.redhat.com/errata/RHSA-2012-0705.html

Note You need to log in before you can comment on or make changes to this bug.