Bug 640241 (CVE-2010-3452) - CVE-2010-3452 OpenOffice.org: Integer signedness error (crash) by processing certain RTF tags
Summary: CVE-2010-3452 OpenOffice.org: Integer signedness error (crash) by processing ...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2010-3452
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 642175 642176 642184 642185 642192 642196 642200 642201 804532
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-10-05 10:23 UTC by Jan Lieskovsky
Modified: 2023-05-11 15:13 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-07-29 13:02:00 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2011:0181 0 normal SHIPPED_LIVE Important: openoffice.org and openoffice.org2 security update 2011-01-28 12:56:23 UTC
Red Hat Product Errata RHSA-2011:0182 0 normal SHIPPED_LIVE Important: openoffice.org security update 2011-01-28 13:02:13 UTC
Red Hat Product Errata RHSA-2011:0183 0 normal SHIPPED_LIVE Important: openoffice.org security and bug fix update 2011-01-28 15:24:30 UTC

Description Jan Lieskovsky 2010-10-05 10:23:25 UTC
An integer signedness error, leading to heap-based buffer out-ouf-bounds
read was found in the way OpenOffice.org processed certain Rich Text Format
(RTF) tags. If a user opened a specially-crafted RTF file in OpenOffice.org
suite tool (oowriter), it could lead to denial of service (oowriter executable
crash), or possibly, execute arbitrary code with the privileges of the user running OpenOffice.org Writer. 


References:
[1] http://www.cs.brown.edu/people/drosenbe/research.html

Acknowledgements:

Red Hat would like to thank OpenOffice.org for reporting this issue. Upstream acknowledges Dan Rosenberg of Virtual Security Research as the original reporter.

Comment 12 Huzaifa S. Sidhpurwala 2011-01-27 03:49:18 UTC
Public via:
http://www.openoffice.org/security/cves/CVE-2010-3451_CVE-2010-3452.html

Comment 13 errata-xmlrpc 2011-01-28 12:56:54 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 4

Via RHSA-2011:0181 https://rhn.redhat.com/errata/RHSA-2011-0181.html

Comment 14 errata-xmlrpc 2011-01-28 13:02:35 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2011:0182 https://rhn.redhat.com/errata/RHSA-2011-0182.html

Comment 15 errata-xmlrpc 2011-01-28 15:25:00 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2011:0183 https://rhn.redhat.com/errata/RHSA-2011-0183.html


Note You need to log in before you can comment on or make changes to this bug.