Red Hat Bugzilla – Bug 821726
CVE-2012-1149 openoffice.org, libreoffice: Integer overflows, leading to heap-buffer overflows in JPEG, PNG and BMP reader implementations
Last modified: 2016-03-04 06:58:36 EST
Multiple integer overflows, leading to heap-based buffer overflows were found in the way JPEG, PNG and BMP image file reader implementations of the LibreOffice and OpenOffice.org application suites performed scanning / loading of JPEG, PNG and BMP image files. A remote attacker could provide a specially-crafted JPEG, PNG or BMP image file, which once opened by a victim in an application from the LibreOffice or OpenOffice.org application suite would lead to that application crash, or, potentially arbitrary code execution with the privileges of the user running the application.
This issue affects the versions of the openoffice.org package, as shipped with Red Hat Enterprise Linux 5 and 6.
This issue affects the versions of the libreoffice package, as shipped with Fedora release of 15 and 16.
Upstream acknowledges Tielei Wang via Secunia SVCRP as the original reporter of this issue.
Preliminary embargo date, proposed by upstream, is tomorrow, Wednesday, 16-th May 2012 at 14:00 UTC time.
Created attachment 584889 [details]
(In reply to comment #5)
> Created attachment 584889 [details]
> RHEL-5 backport
applies and works for RHEL-6 too
LibreOffice upstream advisory:
OpenOffice.org upstream advisory:
Created libreoffice tracking bugs for this issue
Affects: fedora-all [bug 822216]
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2012:0705 https://rhn.redhat.com/errata/RHSA-2012-0705.html