Multiple integer overflows, leading to heap-based buffer overflows were found in the way JPEG, PNG and BMP image file reader implementations of the LibreOffice and OpenOffice.org application suites performed scanning / loading of JPEG, PNG and BMP image files. A remote attacker could provide a specially-crafted JPEG, PNG or BMP image file, which once opened by a victim in an application from the LibreOffice or OpenOffice.org application suite would lead to that application crash, or, potentially arbitrary code execution with the privileges of the user running the application. Upstream patches: [1] http://cgit.freedesktop.org/libreoffice/core/commit/?id=fe40da4cb640819d869d1c925869bc87ede9bbfe [2] http://cgit.freedesktop.org/libreoffice/core/commit/?id=88e0fa4aa3bea9ffeee372b6a428ca62cee41203 [3] http://cgit.freedesktop.org/libreoffice/core/commit/?id=9ff94ae0fa947c5fd6a31fbc38421f60eb5e1fba
This issue affects the versions of the openoffice.org package, as shipped with Red Hat Enterprise Linux 5 and 6. -- This issue affects the versions of the libreoffice package, as shipped with Fedora release of 15 and 16.
Acknowledgements: Upstream acknowledges Tielei Wang via Secunia SVCRP as the original reporter of this issue.
Preliminary embargo date, proposed by upstream, is tomorrow, Wednesday, 16-th May 2012 at 14:00 UTC time.
Created attachment 584889 [details] RHEL-5 backport
(In reply to comment #5) > Created attachment 584889 [details] > RHEL-5 backport applies and works for RHEL-6 too
LibreOffice upstream advisory: [4] http://www.libreoffice.org/advisories/cve-2012-1149/ OpenOffice.org upstream advisory: [5] http://www.openoffice.org/security/cves/CVE-2012-1149.html
Created libreoffice tracking bugs for this issue Affects: fedora-all [bug 822216]
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Via RHSA-2012:0705 https://rhn.redhat.com/errata/RHSA-2012-0705.html