Bug 821726 (CVE-2012-1149) - CVE-2012-1149 openoffice.org, libreoffice: Integer overflows, leading to heap-buffer overflows in JPEG, PNG and BMP reader implementations
Summary: CVE-2012-1149 openoffice.org, libreoffice: Integer overflows, leading to heap...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2012-1149
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 822216 822966 822967 822969 822970
Blocks: 821911
TreeView+ depends on / blocked
 
Reported: 2012-05-15 12:56 UTC by Jan Lieskovsky
Modified: 2023-05-12 17:03 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-08-24 15:54:13 UTC
Embargoed:


Attachments (Terms of Use)
RHEL-5 backport (7.48 KB, patch)
2012-05-16 08:14 UTC, Caolan McNamara
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2012:0705 0 normal SHIPPED_LIVE Important: openoffice.org security update 2012-06-05 00:56:53 UTC

Description Jan Lieskovsky 2012-05-15 12:56:38 UTC
Multiple integer overflows, leading to heap-based buffer overflows were found in the way JPEG, PNG and BMP image file reader implementations of the LibreOffice and OpenOffice.org application suites performed scanning / loading of JPEG, PNG and BMP image files. A remote attacker could provide a specially-crafted JPEG, PNG or BMP image file, which once opened by a victim in an application from the LibreOffice or OpenOffice.org application suite would lead to that application crash, or, potentially arbitrary code execution with the privileges of the user running the application.

Upstream patches:
[1] http://cgit.freedesktop.org/libreoffice/core/commit/?id=fe40da4cb640819d869d1c925869bc87ede9bbfe
[2] http://cgit.freedesktop.org/libreoffice/core/commit/?id=88e0fa4aa3bea9ffeee372b6a428ca62cee41203
[3] http://cgit.freedesktop.org/libreoffice/core/commit/?id=9ff94ae0fa947c5fd6a31fbc38421f60eb5e1fba

Comment 2 Jan Lieskovsky 2012-05-15 13:01:09 UTC
This issue affects the versions of the openoffice.org package, as shipped with Red Hat Enterprise Linux 5 and 6.

--

This issue affects the versions of the libreoffice package, as shipped with Fedora release of 15 and 16.

Comment 3 Jan Lieskovsky 2012-05-15 13:41:13 UTC
Acknowledgements:

Upstream acknowledges Tielei Wang via Secunia SVCRP as the original reporter of this issue.

Comment 4 Jan Lieskovsky 2012-05-15 13:42:45 UTC
Preliminary embargo date, proposed by upstream, is tomorrow, Wednesday, 16-th May 2012 at 14:00 UTC time.

Comment 5 Caolan McNamara 2012-05-16 08:14:53 UTC
Created attachment 584889 [details]
RHEL-5 backport

Comment 6 Caolan McNamara 2012-05-16 13:54:30 UTC
(In reply to comment #5)
> Created attachment 584889 [details]
> RHEL-5 backport

applies and works for RHEL-6 too

Comment 7 Jan Lieskovsky 2012-05-16 15:58:00 UTC
LibreOffice upstream advisory:
[4] http://www.libreoffice.org/advisories/cve-2012-1149/

OpenOffice.org upstream advisory:
[5] http://www.openoffice.org/security/cves/CVE-2012-1149.html

Comment 8 Jan Lieskovsky 2012-05-16 16:24:26 UTC
Created libreoffice tracking bugs for this issue

Affects: fedora-all [bug 822216]

Comment 12 errata-xmlrpc 2012-06-05 01:11:06 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5
  Red Hat Enterprise Linux 6

Via RHSA-2012:0705 https://rhn.redhat.com/errata/RHSA-2012-0705.html


Note You need to log in before you can comment on or make changes to this bug.