<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>138545</bug_id>
          
          <creation_ts>2006-06-29 21:34 0000</creation_ts>
          <short_desc>app-office/openoffice &lt;2.0.3 - multiple vulnerabilities (CVE-2006-2199, CVE-2006-2198, CVE-2006-3117)</short_desc>
          <delta_ts>2006-07-28 13:51:21 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Other</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.openoffice.org/security/bulletin-20060629.html</bug_file_loc>
          <status_whiteboard>A2 [glsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>chazefroy@gmail.com</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>bugzilla@lourdas.name</cc>
    
    <cc>eselect@gentoo.org</cc>
    
    <cc>jakuhr-linux@gmx.de</cc>
    
    <cc>jesus.de.santos@gmail.com</cc>
    
    <cc>jon@severinsson.net</cc>
    
    <cc>maekke@gentoo.org</cc>
    
    <cc>openoffice@gentoo.org</cc>
    
    <cc>rockoo@gmail.com</cc>
    
    <cc>sgtphou@fire-eyes.org</cc>
    
    <cc>siryes@gmail.com</cc>

      

      
          <long_desc isprivate="0">
            <who>chazefroy@gmail.com</who>
            <bug_when>2006-06-29 21:34:39 0000</bug_when>
            <thetext>*  performance improvements: for example, a 23 percent improvement in certain Calc benchmarks
* further improvements to file format compatibility with Microsoft Office files
* new email integration features for users wanting to send emails in Microsoft file formats
* more control over how exported PDF documents will display when opened in a PDF reader
* support for more languages and improvements in hyphenation and thesaurus
* support for Intel architecture for Mac OS X plus improved Mac OS X System integration
* built-in check for updated versions</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>solar@gentoo.org</who>
            <bug_when>2006-06-29 23:09:37 0000</bug_when>
            <thetext>Youi left out the most important part from the release notes..

We also recommend OpenOffice.org 2.0.3 because it includes important security fixes. These have not been exploited but all users of any prior version of OpenOffice.org are urged to download 2.0.3. A standalone patch will be available soon. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>anpereir@gentoo.org</who>
            <bug_when>2006-06-29 23:15:42 0000</bug_when>
            <thetext>http://www.openoffice.org/security/bulletin-20060629.html

Security Bulletin 2006-06-29

OpenOffice.org 2.0.3 fixes three security vulnerabilites that have been found through internal security audits. Although there are currently no known exploits, we urge all users of 2.0.x prior to 2.0.2 to upgrade to the new version or install their vendor&apos;s patches accordingly. Patches for users of OpenOffice.org 1.1.5 will be available shortly.

The three vulnerabilities involve:

    * Java Applets, CVE-2006-2199
    * Macro, CVE-2006-2198; and
    * File Format, CVE-2006-3117</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>anpereir@gentoo.org</who>
            <bug_when>2006-06-29 23:20:31 0000</bug_when>
            <thetext>*** Bug 138546 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>anpereir@gentoo.org</who>
            <bug_when>2006-06-29 23:21:25 0000</bug_when>
            <thetext>*** Bug 138547 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2006-06-30 03:39:53 0000</bug_when>
            <thetext>*** Bug 138567 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2006-06-30 04:35:29 0000</bug_when>
            <thetext>cc maintainers</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-06-30 08:07:17 0000</bug_when>
            <thetext>openoffice please provide updated ebuilds.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jon@severinsson.net</who>
            <bug_when>2006-06-30 13:35:06 0000</bug_when>
            <thetext>And 2.0.3 is supposed to work out-of-the box as native amd64!
I want ;)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2006-07-01 00:11:01 0000</bug_when>
            <thetext>Just got back from GUADEC, so give me some time to get back on speed. Anyway, openoffice-bin should be done soon, source-built version could take a little longer, as ooo-build didn&apos;t provide a release until now (though there is one for RC7 which I could maybe use, didn&apos;t check until now).</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2006-07-02 22:57:37 0000</bug_when>
            <thetext>New version of openoffice-bin and openoffice are in now, please test accordingly</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-07-03 00:46:06 0000</bug_when>
            <thetext>Thx Andreas.

Arches please test and mark stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2006-07-04 17:42:36 0000</bug_when>
            <thetext>This will also cause eselect-1.0.2 to go stable.  Might want to verify with those folks that they are ready for it.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pylon@gentoo.org</who>
            <bug_when>2006-07-05 00:49:09 0000</bug_when>
            <thetext>Stable on ppc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2006-07-05 01:01:09 0000</bug_when>
            <thetext>(In reply to comment #12)
&gt; This will also cause eselect-1.0.2 to go stable.  Might want to verify with
&gt; those folks that they are ready for it.
&gt; 

And also: eselect-oodict and all the myspell dictionaries, otherwise the users won&apos;t have the possibility to spell check anymore. Both should be straightforward though.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-07-05 02:36:37 0000</bug_when>
            <thetext>CC&apos;ing eselect.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>weeve@gentoo.org</who>
            <bug_when>2006-07-06 08:45:31 0000</bug_when>
            <thetext>SPARC is ready to go stable once we hear from the eselect folks.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rapsure@sfcn.org</who>
            <bug_when>2006-07-08 23:16:30 0000</bug_when>
            <thetext>eselect and oodict don&apos;t work on AMD64, so openoffice-bin and a multilib install on AMD64 don&apos;t have spellcheck, and this prevents me from using openoffice-bin 2.0.3</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2006-07-08 23:41:14 0000</bug_when>
            <thetext>(In reply to comment #17)
&gt; eselect and oodict don&apos;t work on AMD64, so openoffice-bin and a multilib
&gt; install on AMD64 don&apos;t have spellcheck, and this prevents me from using
&gt; openoffice-bin 2.0.3
&gt; 

That has already been fixed yesterday, do an emerge sync and try again
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kugelfang@gentoo.org</who>
            <bug_when>2006-07-11 01:53:46 0000</bug_when>
            <thetext>Eselect team is fine with stabling 1.0.2. 1.0.3 is no option as it&apos;s still in
p.mask due to one unported module.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2006-07-12 06:13:24 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2006-07-14 04:52:05 0000</bug_when>
            <thetext>@x86, AMD-64-herd: At least openoffice-bin should be trivial to mark stable, so any hope in getting this done soonish? </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2006-07-14 04:54:42 0000</bug_when>
            <thetext>Hmm, obviously both amd64 and x86-herds were never added, done this now. btw, as the title does not point this out: This security issues affects both openoffice and openoffice-bin</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2006-07-14 05:55:25 0000</bug_when>
            <thetext>1) -bin emerges fine

2) QA: there are a lot of textrels...should I post the log?

3) tested some functions in writer, impress and calc (import of MS documents e.g.) -&gt; works

Sorry no time to test the normal build...am leaving for the weekend soon.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2006-07-14 10:22:02 0000</bug_when>
            <thetext>(In reply to comment #23)
&gt; 2) QA: there are a lot of textrels...should I post the log?

No, those are known. But as we use the upstream binary, there is nothing we can do about it anyway</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>metalgod@gentoo.org</who>
            <bug_when>2006-07-14 19:02:31 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>metalgod@gentoo.org</who>
            <bug_when>2006-07-14 19:04:09 0000</bug_when>
            <thetext>(In reply to comment #8)
&gt; And 2.0.3 is supposed to work out-of-the box as native amd64!
&gt; I want ;)
&gt; 

regarding to this comment i didn&apos;t tried to build from source afaik it doesn&apos;t work. But for somehow it works please cc amd64 team or me so we can start testing it and keyword.

Thanks</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2006-07-15 07:10:21 0000</bug_when>
            <thetext>I tried building it on x86 (with USE=&quot;firefox&quot;), but it failed because dev-libs/nspr-4.6.2 is needed (stable version is 4.6.1-r2). See bug #139453. </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jesus.de.santos@gmail.com</who>
            <bug_when>2006-07-15 09:32:00 0000</bug_when>
            <thetext>x86 here. After several hours compiling it works fine with this options:

[ebuild   R   ] app-office/openoffice-2.0.3  USE=&quot;eds gnome gtk pam xml -binfilter -cairo -debug -firefox -java -kde -ldap -mono -odk&quot; LINGUAS=&quot;-af -ar -be_BY -bg -bn -bs -ca -cs -cy -da -de -el -en -en_GB -en_US -en_ZA -es -et -fa -fi -fr -gu_IN -he -hi_IN -hr -hu -it -ja -km -ko -lt -mk -nb -nl -nn -nr -ns -pa_IN -pl -pt -pt_BR -ru -rw -sh_YU -sk -sl -sr_CS -st -sv -sw_TZ -th -tn -tr -ts -vi -xh -zh_CN -zh_TW -zu&quot; 0 kB

I have tested each module (write, presentation...)
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tsunam@gentoo.org</who>
            <bug_when>2006-07-15 15:58:13 0000</bug_when>
            <thetext>x86 is done after many hours of compiling :(

&gt;^.^&lt;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2006-07-15 23:35:59 0000</bug_when>
            <thetext>I&apos;ve removed the vulnerable versions now from the tree, so I think we should be fine for the GLSA

Reopening as this is really not fixed until this is issued</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wolf31o2@gentoo.org</who>
            <bug_when>2006-07-16 08:31:10 0000</bug_when>
            <thetext>Updated in the 2006.1 snapshot, so I&apos;m removing release@gentoo.org</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2006-07-18 10:39:48 0000</bug_when>
            <thetext>So what is keeping the GLSA from being issued?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-07-22 13:16:55 0000</bug_when>
            <thetext>Just returning from vacation, I&apos;ll look into it tomorrow.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dercorny@gentoo.org</who>
            <bug_when>2006-07-28 13:51:21 0000</bug_when>
            <thetext>GLSA 200607-12

Finally. Thanks everybody!</thetext>
          </long_desc>
      
    </bug>

</bugzilla>