<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>170828</bug_id>
          
          <creation_ts>2007-03-14 09:03 0000</creation_ts>
          <short_desc>app-office/openoffice{-bin} Multiple issues CVE-2007-{0002|023{8|9}}</short_desc>
          <delta_ts>2007-04-17 22:34:44 0000</delta_ts>
          
          
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://support.novell.com/techcenter/psdb/45b2a4c2c1b2b8002e0b1a73efd03241.html</bug_file_loc>
          <status_whiteboard>B2 [glsa] Falco</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>173175</dependson>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>caleb@gentoo.org</cc>
    
    <cc>juantxorena@gmail.com</cc>
    
    <cc>mike.delorme@gmail.com</cc>
    
    <cc>mlangc@gmx.at</cc>
    
    <cc>pauldv@gentoo.org</cc>
    
    <cc>suka@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-14 09:03:32 0000</bug_when>
            <thetext>CVE-2007-0002: Various problems were fixed in the Wordperfect converter library libwpd in OpenOffice_org which could be used by remote attackers to potentially execute code or crash OpenOffice_org. 
 CVE-2007-0238: A stack overflow in the StarCalc parser could be used by remote attackers to potentially execute code by supplying a crafted document. 
 CVE-2007-0239: A shell quoting problem when opening URLs was fixed which could be used by remote attackers to execute code by supplying a crafted document and making the user click on an embedded link.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-03-14 13:24:41 0000</bug_when>
            <thetext>Ccing herd</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2007-03-14 13:40:04 0000</bug_when>
            <thetext>Very non-helpful description from Novell. Tough to figure out, when or where this is fixed. As Novell is using ooo-build, I guess the latest unstable release of OOo should be fine (tough we might have to revision bump it, as the fix might have come in one of the silent patchset-updates we did). About 2.0.4: No clue. openoffice-bin is even more up in the air...

Anyway, to much guessing here, so will try to catch someone from Novell about that.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-14 13:49:20 0000</bug_when>
            <thetext>I think the fixes should be in the upcoming 2.2 scheduled for release late this month.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2007-03-14 14:22:27 0000</bug_when>
            <thetext>(In reply to comment #3)
&gt; I think the fixes should be in the upcoming 2.2 scheduled for release late this
&gt; month.
&gt; 

Ok, so what I&apos;ve found out now: The report was more or less issued by accident, this should have waited until 2.2.

openoffice-bin-2.2-rcs should be fine 2.1 is NOT. Unfortunately for binary patches or the new stable release we have to wait for upstream.

openoffice-2.1.0 currently in portage is also NOT fixed (with the exception of the libwpd-fix)

That&apos;s as bad as we stand now.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-14 14:57:41 0000</bug_when>
            <thetext>Updating whiteboard.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2007-03-14 16:29:50 0000</bug_when>
            <thetext>I have the necessary patches for openoffice-2.1.0 now, am building right now. Will be doing a revision bump with this patches afterwards, I guess we should mark this stable asap. (OOo 2.1.0 is ready for going stable anyway)

For openoffice-bin I&apos;m afraid we have to wait for the 2.2-release.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2007-03-15 11:08:07 0000</bug_when>
            <thetext>openoffice-2.1.0-r1 (including the security patches) built fine, so the question now is: How do we handle this? Should I put it into portage (and if yes mention this bug?) or wait until we have a fixed binary version, too?

Never had such a situation, so waiting for advice.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-15 18:18:54 0000</bug_when>
            <thetext>Yes it is kind of akward. Our normal procedure is to put it into Portage and only mention this bug. Did any other vendors put out fixes and sources?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2007-03-15 21:47:08 0000</bug_when>
            <thetext>(In reply to comment #8)
&gt; Yes it is kind of akward. Our normal procedure is to put it into Portage and
&gt; only mention this bug. Did any other vendors put out fixes and sources?
&gt; 

Not that I know of, but I guess you are better in checking this than me...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-16 08:16:02 0000</bug_when>
            <thetext>CVE-2007-0002 is definately public.

It appears that the other issues are public here:

https://www.redhat.com/archives/fedora-cvs-commits/2007-February/msg01237.html

If that is the case just go ahead and commit.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2007-03-16 09:07:12 0000</bug_when>
            <thetext>2.1.0-r1 is in portage now, so I guess the work to mark it stable can start.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2007-03-16 09:42:32 0000</bug_when>
            <thetext>I&apos;ve also commited the most current RC of openoffice-bin-2.2, which should have those fixes too. Though as it being a RC I&apos;ve hard-masked it. I guess we should wait for the final with this (which is scheduled for next Thursday atm)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-16 10:01:24 0000</bug_when>
            <thetext>Thx Suka.

Arch Security Liaisons please test and mark stable:

openoffice-2.1.0-r1.ebuild:KEYWORDS=&quot;~amd64 ppc sparc x86&quot;
openoffice-bin-2.2.0_rc3.ebuild:KEYWORDS=&quot;amd64 x86&quot;

Looks like sparc will be a problem and could need a mask.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2007-03-16 10:07:33 0000</bug_when>
            <thetext>(In reply to comment #13)
&gt; Thx Suka.
&gt; 
&gt; Arch Security Liaisons please test and mark stable:
&gt; 
&gt; openoffice-2.1.0-r1.ebuild:KEYWORDS=&quot;~amd64 ppc sparc x86&quot;
&gt; openoffice-bin-2.2.0_rc3.ebuild:KEYWORDS=&quot;amd64 x86&quot;
&gt; 
&gt; Looks like sparc will be a problem and could need a mask.
&gt; 

Just to re-emphasize this: Do we really want to mark a release candidate stable? Shouldn&apos;t we wait for the final?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-16 10:50:26 0000</bug_when>
            <thetext>Ok, valid point. To rephrase:

Arch Security Liaisons please test and mark stable:
 
openoffice-2.1.0-r1.ebuild:KEYWORDS=&quot;~amd64 ppc sparc x86&quot;

And at your option mark the release candidate stable, otherwise we&apos;ll wait for the final which should hopefully arrive before the end of the month.

openoffice-bin-2.2.0_rc3.ebuild:KEYWORDS=&quot;amd64 x86&quot;
 
Looks like sparc will be a problem and could need a mask.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-03-16 13:23:00 0000</bug_when>
            <thetext>The sparc aspect of things is somewhat complex:
openoffice-2.0.* only works with the current stable toolchain (gcc-3.4.x)
&gt;=openoffice-2.1 only works with the new toolchain (gcc-4.1.x, shipping for 2007.0) - but we just got it to build, not work correctly yet. gcc4 is required because of STLport-5.1.0. I&apos;m working with suka on getting 2.1+ into some working form, though it&apos;s currently not high-priority in my list.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-25 07:01:55 0000</bug_when>
            <thetext>Arch security liaisons, any news on this one?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-03-25 10:35:11 0000</bug_when>
            <thetext>(In reply to comment #17)
&gt; Arch security liaisons, any news on this one?

Compiles fine on ppc (tested several combinations of use-flags), what about =sys-libs/db-4.3.29-r2 which also needs to be marked stable? Someone already talked to caleb/paul about that?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-25 11:04:40 0000</bug_when>
            <thetext>Pulling in paul and caleb to advise on any possible problems related to the =sys-libs/db-4.3.29-r2 dep.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pauldv@gentoo.org</who>
            <bug_when>2007-03-25 20:47:36 0000</bug_when>
            <thetext>The db version can certainly be stabilized, it hasn&apos;t changed interestingly for over half a year. I don&apos;t think strict requirements are wise though. It is also not needed as this version is the only 4.3 version around.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2007-03-25 21:06:27 0000</bug_when>
            <thetext>Hmmm, maybe I just don&apos;t get it, but what =sys-libs/db-4.3.29-r2 dep are you talking about?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-25 21:14:00 0000</bug_when>
            <thetext>@suka: sys-libs/db-4.3.29-r2 is pulled in by the &gt;=sys-libs/db-4.3 dep and latest stable on any arch it appears is sys-libs/db-4.2.52_p4-r2.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2007-03-25 21:22:07 0000</bug_when>
            <thetext>(In reply to comment #22)
&gt; @suka: sys-libs/db-4.3.29-r2 is pulled in by the &gt;=sys-libs/db-4.3 dep and
&gt; latest stable on any arch it appears is sys-libs/db-4.2.52_p4-r2.
&gt; 

Yeah, I know, I just wanted to point out that there is no strict dependency on that one version like Paul seems to have thought.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2007-03-29 12:18:58 0000</bug_when>
            <thetext>openoffice-bin-2.2.0  is in the tree now, so please look at it and mark stable (and don&apos;t forget about openoffice...)

maybe we should make this bug public again?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-03-29 14:08:12 0000</bug_when>
            <thetext>I can&apos;t connect to the CVS server so no target keywords. Archs if you are in doubt just post on this bug.

Opening bug since this is public now.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-03-29 17:47:14 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2007-03-29 23:19:24 0000</bug_when>
            <thetext>openoffice-bin-2.2.0 stable on x86.

Sorry, I do not have time to compile OOo from source - laptop has to go with me to work tomorrow, where it will be tortured by booting Windows on it.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-03-31 05:36:14 0000</bug_when>
            <thetext>2.1.0-r1 stable on x86</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caleb@gentoo.org</who>
            <bug_when>2007-03-31 11:33:32 0000</bug_when>
            <thetext>agreed with paul - there should be no issues marking db 4.3 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>mlangc@gmx.at</who>
            <bug_when>2007-03-31 19:04:24 0000</bug_when>
            <thetext>maybe someone should check if bug 172860 is x86 specific before stabling continues . according to bug 172860 comment #3 this is quite possible, but who knows...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>angelos@gentoo.org</who>
            <bug_when>2007-04-02 20:33:56 0000</bug_when>
            <thetext>openoffice-bin-2.2.0 emerges fine and works on amd64, as it&apos;s -bin it&apos;s not affected by bug 172860
openoffice-2.1.0-r1 emerges fine and works for me too, but that&apos;s never marked stable on amd64 :&gt;

Portage 2.1.2.2 (default-linux/amd64/2006.1/desktop, gcc-4.1.1, glibc-2.5-r0, 2.6.20-beyond2 x86_64)
=================================================================
System uname: 2.6.20-beyond2 x86_64 AMD Athlon(tm) 64 X2 Dual Core Processor 4600+
Gentoo Base System release 1.12.9
Timestamp of tree: Mon, 02 Apr 2007 10:50:01 +0000
ccache version 2.4 [enabled]
dev-java/java-config: 1.3.7, 2.0.31
dev-lang/python:     2.4.3-r4
dev-python/pycrypto: 2.0.1-r5
dev-util/ccache:     2.4-r6
sys-apps/sandbox:    1.2.17
sys-devel/autoconf:  2.13, 2.61
sys-devel/automake:  1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
sys-devel/binutils:  2.16.1-r3
sys-devel/gcc-config: 1.3.14
sys-devel/libtool:   1.5.22
virtual/os-headers:  2.6.17-r2
ACCEPT_KEYWORDS=&quot;amd64&quot;
AUTOCLEAN=&quot;yes&quot;
CBUILD=&quot;x86_64-pc-linux-gnu&quot;
CFLAGS=&quot;-march=k8 -O2 -pipe -msse3 -w&quot;
CHOST=&quot;x86_64-pc-linux-gnu&quot;
CONFIG_PROTECT=&quot;/etc /usr/share/X11/xkb&quot;
CONFIG_PROTECT_MASK=&quot;/etc/env.d /etc/env.d/java/ /etc/gconf /etc/java-config/vms/ /etc/php/apache1-php5/ext-active/ /etc/php/apache2-php5/ext-active/ /etc/php/cgi-php5/ext-active/ /etc/php/cli-php5/ext-active/ /etc/revdep-rebuild /etc/splash /etc/terminfo&quot;
CXXFLAGS=&quot;-march=k8 -O2 -pipe -msse3 -w&quot;
DISTDIR=&quot;/usr/portage/distfiles&quot;
EMERGE_DEFAULT_OPTS=&quot;--quiet&quot;
FEATURES=&quot;buildsyspkg ccache collision-protect distlocks metadata-transfer multilib-strict parallel-fetch sandbox sfperms strict test&quot;
GENTOO_MIRRORS=&quot;ftp://linux.rz.ruhr-uni-bochum.de/gentoo-mirror/ ftp://ftp.uni-erlangen.de/pub/mirrors/gentoo ftp://ftp.join.uni-muenster.de/pub/linux/distributions/gentoo ftp://ftp.wh2.tu-dresden.de/pub/mirrors/gentoo ftp://ftp.join.uni-muenster.de/pub/linux/distributions/gentoo ftp://ftp-stud.fht-esslingen.de/pub/Mirrors/gentoo/ ftp://ftp.gentoo.mesh-solutions.com/gentoo/ ftp://pandemonium.tiscali.de/pub/gentoo/ &quot;
LANG=&quot;en_US.ISO8859-15&quot;
LC_ALL=&quot;en_US.ISO8859-15&quot;
MAKEOPTS=&quot;-j3 -l3 -s --no-print-directory&quot;
PKGDIR=&quot;/usr/portage/packages&quot;
PORTAGE_RSYNC_EXTRA_OPTS=&quot;--exclude-from=/etc/portage/rsync_excludes&quot;
PORTAGE_RSYNC_OPTS=&quot;--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages --filter=H_**/files/digest-*&quot;
PORTAGE_TMPDIR=&quot;/var/tmp&quot;
PORTDIR=&quot;/usr/portage&quot;
PORTDIR_OVERLAY=&quot;/usr/local/portage/overlay&quot;
SYNC=&quot;rsync://rsync.europe.gentoo.org/gentoo-portage&quot;
USE=&quot;X a52 aac acpi alsa amd64 amr audiofile berkdb bitmap-fonts bzip2 cairo cdinstall cdr cli cracklib crypt cups dbus dri dts dvd dvdr dvdread emboss encode fam firefox fortran gdbm gif gpm gstreamer gtk gtk2 hal iconv jpeg libg++ logrotate mad midi mikmod mp3 mpeg ncurses nptl nptlonly offensive ogg opengl pam pcre php png ppds pppd quicktime readline reflection sdl session smp spl ssl svg symlink tcpd test tiff truetype truetype-fonts type1-fonts unicode v4l vim vorbis x264 xinerama xorg xv xvid zlib&quot; ALSA_CARDS=&quot;emu10k1&quot; ALSA_PCM_PLUGINS=&quot;adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mulaw multi null plug rate route share shm softvol&quot; ELIBC=&quot;glibc&quot; INPUT_DEVICES=&quot;evdev keyboard&quot; KERNEL=&quot;linux&quot; LCD_DEVICES=&quot;bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text&quot; LIRC_DEVICES=&quot;inputlirc&quot; USERLAND=&quot;GNU&quot; VIDEO_CARDS=&quot;nvidia&quot;
Unset:  CTARGET, INSTALL_MASK, LDFLAGS, LINGUAS, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2007-04-03 05:35:51 0000</bug_when>
            <thetext>We really should get this done soonish. So what&apos;s still missing from my perspective:

AMD64 marking openoffice-bin-2.2.0 stable

sparc deciding on what to do now, as no version of openoffice seems to build atm.

Could we please have feedback on both?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-04-03 13:22:41 0000</bug_when>
            <thetext>Just p.mask it/remove keywords for us.
I&apos;ll look into getting the new one working when i&apos;ve got time which i kind of lack for at least this week.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2007-04-03 14:00:58 0000</bug_when>
            <thetext>(In reply to comment #33)
&gt; Just p.mask it/remove keywords for us.
&gt; I&apos;ll look into getting the new one working when i&apos;ve got time which i kind of
&gt; lack for at least this week.
&gt; 

Ok, I&apos;ll just remove 2.0.4 from the tree then, so this is &quot;sorted out&quot; more or less automatically.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jakub@gentoo.org</who>
            <bug_when>2007-04-04 12:16:14 0000</bug_when>
            <thetext>*** Bug 173338 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>welp@gentoo.org</who>
            <bug_when>2007-04-06 19:28:52 0000</bug_when>
            <thetext>openoffice-bin-2.2.0 is now stable on amd64, openoffice-2.1.0-r1 is already ~amd64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>welp@gentoo.org</who>
            <bug_when>2007-04-06 19:31:29 0000</bug_when>
            <thetext>This time i remembered to remove amd64@... sorry &apos;bout teh bugspam.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>suka@gentoo.org</who>
            <bug_when>2007-04-06 22:25:10 0000</bug_when>
            <thetext>I&apos;ve removed openoffice-bin-2.1.0 from the tree now.

As far as I can see, everything is set for the GLSA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-04-17 22:34:44 0000</bug_when>
            <thetext>200704-12, thanks everybody! sorry for the delay</thetext>
          </long_desc>
      
    </bug>

</bugzilla>