Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 108411 - app-office/{koffice,kword}: heap overflow in rtf import filter (CAN-2005-2971)
Summary: app-office/{koffice,kword}: heap overflow in rtf import filter (CAN-2005-2971)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa] jaervosz
Keywords:
: 106898 (view as bug list)
Depends on:
Blocks:
 
Reported: 2005-10-07 10:43 UTC by Carsten Lohrke (RETIRED)
Modified: 2005-10-14 00:33 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
kword-3.4.1-rtfimport.diff (kword-3.4.1-rtfimport.diff,8.41 KB, text/plain)
2005-10-07 10:44 UTC, Carsten Lohrke (RETIRED)
no flags Details
kword-1.4.1-r1.ebuild (kword-1.4.1-r1.ebuild,1.22 KB, text/plain)
2005-10-07 10:47 UTC, Carsten Lohrke (RETIRED)
no flags Details
advisory-20051010-1.txt (advisory-20051010-1.txt,894 bytes, text/plain)
2005-10-08 06:45 UTC, Carsten Lohrke (RETIRED)
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Carsten Lohrke (RETIRED) gentoo-dev 2005-10-07 10:43:29 UTC
The advisory should follow next monday.
Comment 1 Carsten Lohrke (RETIRED) gentoo-dev 2005-10-07 10:44:50 UTC
Created attachment 70104 [details]
kword-3.4.1-rtfimport.diff
Comment 2 Carsten Lohrke (RETIRED) gentoo-dev 2005-10-07 10:47:41 UTC
Created attachment 70105 [details]
kword-1.4.1-r1.ebuild

For those archs who want to check already... alpha and ppc64 don't have KOffice
1.4 marked stable yet, but the patch applies to KOffice 1.3.5 as well.
Comment 3 Thierry Carrez (RETIRED) gentoo-dev 2005-10-07 11:38:52 UTC
This is CAN-2005-2971
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-10-07 11:39:13 UTC
*** Bug 106898 has been marked as a duplicate of this bug. ***
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-10-07 23:56:42 UTC
Thx Carsten, do you have a draft advisory and an updated kword ebuild? 
     
Calling arch security liaisons:     
     
alpha  kloeri     
amd64  blubb     
ppc  hansmi     
ppc64  tgall     
sparc  gustavoz     
x86  tester    
    
Do NOT commit anything to Portage.   
Comment 6 Simon Stelling (RETIRED) gentoo-dev 2005-10-08 02:18:31 UTC
CC'ing cryos since he's our kde-guy ;)
Comment 7 Carsten Lohrke (RETIRED) gentoo-dev 2005-10-08 06:45:59 UTC
Created attachment 70151 [details]
advisory-20051010-1.txt

(In reply to comment #5)
> Thx Carsten, do you have a draft advisory 

Sure, it's terse, though.

> and an updated kword ebuild? 

Is the one I attached not good enough?
Comment 8 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-10-08 07:40:24 UTC
Sorry I meant koffice, if you want that tested too. 
Comment 9 Marcus D. Hanwell (RETIRED) gentoo-dev 2005-10-08 13:23:07 UTC
Tested kword here. I was able to both save and open rtf files. Is there any 
test rtf file I should be trying? Otherwise amd64 looks good to go here - all 
the normal stuff seems to work as always. 
Comment 10 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-10-08 15:37:19 UTC
Looks good for ppc.
Comment 11 Carsten Lohrke (RETIRED) gentoo-dev 2005-10-08 16:04:01 UTC
Sune: The code is the same...

Marcus: I don't have a test rtf.
Comment 12 Thierry Carrez (RETIRED) gentoo-dev 2005-10-09 09:27:36 UTC
PoC RTF @ http://scary.beasts.org/misc/out27.rtf
Comment 13 Olivier Crete (RETIRED) gentoo-dev 2005-10-10 08:46:15 UTC
I dont do kde... 
Carlo: are you on x86?
Comment 14 Bryan Østergaard (RETIRED) gentoo-dev 2005-10-10 16:26:47 UTC
Good on alpha.
Comment 15 Gustavo Zacarias (RETIRED) gentoo-dev 2005-10-10 19:39:29 UTC
Adding weeve since he's our KDE man(tm) (and my KDE is b0rked).
Comment 16 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-10-11 06:20:55 UTC
1.4.2 released but no apparent mention of this issue. Let's keep this closed 
until their advisory is out. 
 
Note: Good on alpha and ppc so far. 
Comment 17 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-10-11 07:24:54 UTC
This is now public. 
 
Carlo please commit an updated ebuild and we'll call remaining arches to mark 
stable 
Comment 18 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-10-11 07:34:40 UTC
Fixed ebuilds are already in the tree. 
 
Arches please test and mark 1.4.1-r1 or 1.4.2 stable. 
 
KDE, please follow normal security release procedures next time. 
Comment 19 Gregorio Guidi (RETIRED) gentoo-dev 2005-10-11 07:51:16 UTC
I committed the fixed ebuilds a few hours ago, sorry. 
 
The ebuilds that are ready to be marked stable are app-office/koffice-1.4.1-r1 
and app-office/kword-1.4.1-r1. 
ppc64: I see you don't have koffice/kword-1.4.x marked stable, do you think 
you can mark it stable right now or do you prefer to have a patched version of 
koffice/kword-1.3.x too? 
Comment 20 Carsten Lohrke (RETIRED) gentoo-dev 2005-10-11 07:58:31 UTC
I just committed koffice-1.3.5-r3 and kword-1.3.5-r1 for those who don't see
KOffice 1.4 stable on their architecture yet.


(In reply to comment #13)
> I dont do kde... 
> Carlo: are you on x86?

Yes, marked stable already.

Comment 21 Marcus D. Hanwell (RETIRED) gentoo-dev 2005-10-11 08:17:33 UTC
amd64 done. 
Comment 22 Bryan Østergaard (RETIRED) gentoo-dev 2005-10-11 14:14:45 UTC
Alpha done.
Comment 23 Jason Wever (RETIRED) gentoo-dev 2005-10-11 23:51:24 UTC
And on the 7th day, there was SPARC, and it was good.
Comment 24 Joe Jezak (RETIRED) gentoo-dev 2005-10-12 09:14:05 UTC
Marked ppc stable.
Comment 25 Brent Baude (RETIRED) gentoo-dev 2005-10-13 13:31:31 UTC
Marked app-office/koffice-1.4.1-r1 and app-office/kword-1.4.1-r1 and supporting
deps ppc64 today.
Comment 26 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-10-13 13:34:12 UTC
This one is ready for GLSA. 
Comment 27 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-10-14 00:33:38 UTC
GLSA 200510-12 
 
Note: Both Thierry and I voted for GLSA on this one on IRC.