First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 63556
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Tom Lynema <lyz27@yahoo.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 63556 depends on: 65987 Show dependency tree
Bug 63556 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-09-10 08:19 0000
SecurityTracker Alert ID:  1011205
SecurityTracker URL:  http://securitytracker.com/id?1011205
CVE Reference:  GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Sep 10 2004
Impact:  Disclosure of user information
Fix Available:  Yes   Exploit Included:  Yes   Vendor Confirmed:  Yes  
Version(s): 1.1.2
Description:  A vulnerability was reported in OpenOffice. A local user may be able to obtain documents belonging to another local user.

pmladek reported that the software uses insecure temporary files. When started, OpenOffice creates a world-readable temporary directory ('/tmp/sv<RAND>.tmp'). When an OpenOffice file is saved, a compressed version (zip file) is saved in the temporary directory.

A local user can access the temporary directory and obtain the file.
Impact:  A local user can obtain information belonging to another local user.
Solution:  The vendor has issued a fix, available via CVS.
Vendor URL:  www.openoffice.org/issues/show_bug.cgi?id=33357 (Links to External Site)
Cause:  Access control error, State error
Underlying OS:  Linux (Any), UNIX (Any)

Message History:   None. 

Reproducible: Always
Steps to Reproduce:

------- Comment #1 From Thierry Carrez (RETIRED) 2004-09-11 02:59:46 0000 -------
OpenOffice team, please confirm fix

------- Comment #2 From Alin Năstac 2004-09-13 02:14:45 0000 -------
see also http://secunia.com/advisories/12302/

------- Comment #3 From Matthias Geerdsen 2004-09-15 13:46:44 0000 -------
CAN-2004-0752

fixed for Red Hat (RHSA-2004:446-08)

SA12302:
"Solution:
The vulnerability has been fixed in Product Update 3 for StarOffice and a release candidate of OpenOffice 1.1.3."

------- Comment #4 From Matthias Geerdsen 2004-09-16 11:21:28 0000 -------
OpenOffice team, please comment on the status of a fix for this

------- Comment #5 From Paul de Vrieze 2004-09-16 12:47:45 0000 -------
To me this really is a minor issue, I think we can wait until 1.1.3 is out. 

------- Comment #6 From Matthias Geerdsen 2004-09-17 02:41:45 0000 -------
setting status to [upstream]
1.1.3 seems to be coming soon

------- Comment #7 From Andreas Proschofsky 2004-09-18 03:07:58 0000 -------
This is already fixed in openoffice-ximian-1.3.4

------- Comment #8 From Sune Kloppenborg Jeppesen 2004-09-28 01:03:32 0000 -------
Mandrake just released their fix:

http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:103

------- Comment #9 From Matthias Geerdsen 2004-10-05 02:03:35 0000 -------
going back to ebuild status, since 1.1.3 has been released

------- Comment #10 From Matthias Geerdsen 2004-10-07 02:03:24 0000 -------
OpenOffice team, could you please comment on the bug when the OOo ebuilds have
reached stable

security, any votes on a GLSA since this is rated B4?

------- Comment #11 From Thierry Carrez (RETIRED) 2004-10-07 02:13:47 0000 -------
I think we should issue a GLSA. This package is very common, it leaks complete
documents and is really easy. RedHat and Mandrake released advisories on this
too.

------- Comment #12 From Matthias Geerdsen 2004-10-07 05:11:18 0000 -------
Oops... well actually time for some testing and stable marking...
Since only 1.1.2 is said to be affected, we will need the following:

openoffice-bin-1.1.3:
current KEYWORDS="~x86"
target KEYWORDS="x86 amd64"

openoffice-1.1.3:
current KEYWORDS="~x86"
target KEYWORDS="x86"

_____

openoffice-ximian-1.3.4:
target KEYWORDS="~x86 ~ppc" reached already

openoffice-ximian-bin only has 1.1.53, no work needed either

------- Comment #13 From Simon Stelling (RETIRED) 2004-10-10 04:40:53 0000 -------
stable on amd64

------- Comment #14 From Matthias Geerdsen 2004-10-12 01:46:32 0000 -------
Any progress on marking this stable on x86 so far?

This has been in [stable] status for 5 days and has been opened about a month ago already.

------- Comment #15 From Andreas Proschofsky 2004-10-12 08:27:52 0000 -------
openoffice and openoffice-bin 1.1.3 are now stable on x86, still there is a lot
to do:

*) Need to mark a newer openoffice-ximian stable on x86, the current stable
doesn't have the fix. Just commited a new version into unstable which I hope to
mark stable in the next few days.

*) There is no version of openoffice-ximian-bin which is not vulnerable, as we
are depending on upstream binaries (in this case from Ximian) and there is no
newer version, I am going to mask it at whole in package.mask until we get a
newer binary

*) Other archs will have to check all three package:

openoffice-bin:
ppc (now at 1.1.1)

openoffice:
sparc (1.1.0-r4), ppc (1.0.3-r2!)

openoffice-ximian:
ppc (1.1.55), sparc (1.1.61)

------- Comment #16 From Andreas Proschofsky 2004-10-13 02:14:06 0000 -------
openoffice-ximian-bin is now masked, people should upgrade to a recent
openoffice-ximian

------- Comment #17 From Matthias Geerdsen 2004-10-13 09:02:19 0000 -------
Arches... please test and mark stable if possible...


to be on the safe side we should end up with:

openoffice-1.1.3:
current KEYWORDS="x86"
target KEYWORDS="x86 sparc ppc"

openoffice-bin-1.1.3:
current KEYWORDS="x86 amd64"
target KEYWORDS="x86 amd64 ppc"

openoffice-ximian-1.3.5-r1:
current KEYWORDS="~x86 ~ppc"
target KEYWORDS="x86 ppc sparc"


------- Comment #18 From Thierry Carrez (RETIRED) 2004-10-14 01:17:45 0000 -------
Hmmm... In fact we don't need as much, since only 1.1.2 versions are affected.
openoffice and openoffice-bin already have the necessary keywords !

For openoffice-ximian it's slightly more complicated, as we don't "see" the oo
version used. In fact we have:
1.1.55 -> 1.1.1 (unaffected)
1.1.61, -> 1.1.2 (affected)
1.3.4, 1.3.5 -> 1.1.2 but patched (unaffected)

So we just need for openoffice-ximian-1.3.5-r1:
current KEYWORDS="~x86 ~ppc"
target KEYWORDS="x86 ~ppc sparc"

All in all, only x86 and sparc still have keywording work (removing ppc).
However, all arches can/should test and mark stable the latest version if they
can.

------- Comment #19 From Jason Wever (RETIRED) 2004-10-14 21:01:49 0000 -------
So just to be straight, regular plain old openoffice-1.1.1 is not vulnerable,
correct?  I'm just asking as 1.1.2 and 1.1.3 have build problems on sparc right
now and on a good day when things do compile, it takes about 36 hours or so to
build.

------- Comment #20 From Thierry Carrez (RETIRED) 2004-10-15 00:46:19 0000 -------
Yes, 1.1.1 OO.org (and 1.1.1-derived ximian-OO.org) is not vulnerable. The
ppc/gcc3.4/OO113.org build problem does not block this security bug.

------- Comment #21 From Andreas Proschofsky 2004-10-15 08:42:16 0000 -------
Just marked openoffice-ximian 1.3.5-r1 stable, so x86 should be fine

------- Comment #22 From Gustavo Zacarias (RETIRED) 2004-10-18 07:16:41 0000 -------
openoffice-ximian-1.3.5-r1 stable on sparc.

------- Comment #23 From Thierry Carrez (RETIRED) 2004-10-18 08:53:26 0000 -------
So we should be set... vorlon, please draft :)

------- Comment #24 From Thierry Carrez (RETIRED) 2004-10-19 02:31:41 0000 -------
Andreas, wrt comment #15, ximian-openoffice-bin-1.1.53 is 1.1.1-based, right ?
So it wouldn't be affected by this vulnerability ? If so, there would be no
need for security masking (feel free to keep the mask for other reasons).

Please confirm as our GLSA contents depend on it...

------- Comment #25 From Andreas Proschofsky 2004-10-19 02:44:59 0000 -------
@Koon: Yes you are right, my fault, will unmask it again. Thanks for noting

------- Comment #26 From Thierry Carrez (RETIRED) 2004-10-20 14:19:15 0000 -------
GLSA 200410-17

First Last Prev Next    No search results available      Search page      Enter new bug