Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 69624 - app-office/koffice-1.3.4 weak integer overflow vulnerability fix
Summary: app-office/koffice-1.3.4 weak integer overflow vulnerability fix
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo Security
URL: http://www.koffice.org/releases/1.3.4...
Whiteboard: A2 [glsa] koon
Keywords:
Depends on: 69936
Blocks:
  Show dependency tree
 
Reported: 2004-10-31 07:53 UTC by Pablo De Nápoli
Modified: 2004-11-06 05:33 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Pablo De Nápoli 2004-10-31 07:53:52 UTC
Acording to the official Koffice release notes, koffice-1.3.4 has an integer overflow vulnerability fix in KWord's PDF import filter which is weak against compiler optimization.

A patch is available at

http://download.kde.org/stable/koffice-1.3.4/src/patch/koffice_xpdf_1_3_4_security_integer_overflow.diff

Please patch the source with it.

Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Thierry Carrez (RETIRED) gentoo-dev 2004-10-31 08:35:00 UTC
Looks like the original patch introduced in GLSA 200410-30 and bug 68558 may not be sufficient...

KDE team : We might have to repatch this :/
Comment 2 Simone Gotti (RETIRED) gentoo-dev 2004-10-31 08:50:01 UTC
The reported link doesn't works for me.
This one works
ftp://ftp.kde.org/pub/kde/stable/koffice-1.3.4/src/patch/koffice_1_3_4_xpdf_security_integer_overflow.diff

BTW I've noticed that in KDECVS a similar patch was applied also to kpdf, but didn't find any report:

http://lists.kde.org/?l=kde-cvs&m=109895739822113&w=2 >> IT'S WRONG
http://lists.kde.org/?l=kde-cvs&m=109895658125554&w=2 >> IT'S RIGHT BUT APPLIED ON THE UPPER ONE.
Comment 3 Carsten Lohrke (RETIRED) gentoo-dev 2004-10-31 09:06:39 UTC
Can't find/verify gpg signature. The patch looks good, though.

<<< koffice-1.3.3-r2.ebuild
<<< koffice-1.3.4-r1.ebuild

Arch herds, I have to ask you again: Please mark either one of the above ebuilds stable.

ppc64: Would be nice, if you would use the "second chance". I can dump the old ebuilds in one rush then.
Comment 4 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2004-10-31 10:44:42 UTC
Stable on ppc.
Comment 5 Jason Wever (RETIRED) gentoo-dev 2004-10-31 16:55:29 UTC
koffice-1.3.3-r2 stable on sparc
Comment 6 Bryan Østergaard (RETIRED) gentoo-dev 2004-11-01 03:24:03 UTC
1.3.4-r1 stable on alpha.
Comment 7 Jeremy Huddleston (RETIRED) gentoo-dev 2004-11-02 12:38:55 UTC
1.3.4-r1 stable on amd64
Comment 8 Markus Rothe (RETIRED) gentoo-dev 2004-11-02 13:28:14 UTC
1.3.4-r1 stable on ppc64
Comment 9 Thierry Carrez (RETIRED) gentoo-dev 2004-11-03 03:12:12 UTC
Looks the same as (still not public) bug 69662 to me. Patches are different, but I would say they patch the same thing. Can someone with access double-confirm this is a different issue ?
Comment 10 Carsten Lohrke (RETIRED) gentoo-dev 2004-11-03 09:24:17 UTC
Koon: Yes, it is. Koffice is fixed, kdegraphics fixes follow in a few minutes.
Comment 11 Thierry Carrez (RETIRED) gentoo-dev 2004-11-03 12:30:42 UTC
Thanks Carsten for clarification.
We'll probably group xpdf 64 bit GLSAs (or update the old xpdf one).
Comment 12 Thierry Carrez (RETIRED) gentoo-dev 2004-11-05 04:53:41 UTC
Will be released as a 200410-30 update when bug 69936 will be done.
Comment 13 Thierry Carrez (RETIRED) gentoo-dev 2004-11-06 05:33:51 UTC
GLSA 200410-30:02 update out