Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 478284 (CVE-2013-2189) - <app-office/libreoffice-4.0.4.2 <app-office/libreoffice-bin-4.0.4.2 <app-office-openoffice-bin-4.0.1 : two vulnerabilities (CVE-2013-{2189,4156})
Summary: <app-office/libreoffice-4.0.4.2 <app-office/libreoffice-bin-4.0.4.2 <app-offi...
Status: RESOLVED FIXED
Alias: CVE-2013-2189
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [noglsa]
Keywords:
Depends on: 477532
Blocks:
  Show dependency tree
 
Reported: 2013-07-26 19:59 UTC by Agostino Sarubbo
Modified: 2013-11-13 09:08 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-07-26 19:59:26 UTC
From https://bugzilla.redhat.com/show_bug.cgi?id=988832 :

A NULL pointer dereference flaw was found in the way Apache OpenOffice and LibreOffice, office 
productivity suites, used to previously handle certain Microsoft Office Open XML format / Microsoft 
Office Word Macro-Enabled (DOCM) documents. A remote attacker could provide a specially-crafted 
DOCM format file that, when processed in some application from the Apache OpenOffice or LibreOffice 
suites would lead to that applications crash.

References:
[1] http://www.openoffice.org/security/cves/CVE-2013-4156.html
[2] http://www.libreoffice.org/advisories/cve-2013-4156/
Comment 1 Agostino Sarubbo gentoo-dev 2013-07-26 19:59:30 UTC
From https://bugzilla.redhat.com/show_bug.cgi?id=988834 :

A security flaw was found in the way Apache OpenOffice and LibreOffice, office productivity suites, 
previously used to handle certain, invalid PLCF (Plex of Character Positions in File) elements when 
parsing selected Microsoft Office Word (DOC) format documents. A remote attacker could provide a 
specially-crafted DOC format file that, when processed in some application from the Apache 
OpenOffice or LibreOffice suites would lead to that application crash or, potentially, arbitrary 
code execution with the privileges of the user running the application.

References:
[1] http://www.openoffice.org/security/cves/CVE-2013-2189.html
[2] http://www.libreoffice.org/advisories/CVE-2013-2189/


@maintainer(s): after the bump, in case we need to stabilize the package, please say explicitly if it is ready for the stabilization or not.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2013-08-27 02:55:53 UTC
CVE-2013-4156 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4156):
  Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a
  denial of service (memory corruption) or possibly have unspecified other
  impact via a crafted element in an OOXML document file.

CVE-2013-2189 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2189):
  Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a
  denial of service (memory corruption) or possibly have unspecified other
  impact via invalid PLCF data in a DOC document file.
Comment 3 Chí-Thanh Christopher Nguyễn gentoo-dev 2013-10-05 19:05:05 UTC
(In reply to Agostino Sarubbo from comment #1)
> @maintainer(s): after the bump, in case we need to stabilize the package,
> please say explicitly if it is ready for the stabilization or not.

Next time CC app-office/openoffice-bin maintainer (me) too, please

Arches, please stabilize app-office/openoffice-bin-4.0.1

Target keywords: amd64 x86
Comment 4 Agostino Sarubbo gentoo-dev 2013-10-11 14:02:03 UTC
amd64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2013-10-11 14:02:25 UTC
x86 stable
Comment 6 Chí-Thanh Christopher Nguyễn gentoo-dev 2013-10-12 15:10:03 UTC
Vulnerable versions have been removed from the tree.
Comment 7 Andreas K. Hüttel archtester gentoo-dev 2013-10-21 22:13:59 UTC
(In reply to Chí-Thanh Christopher Nguyễn from comment #6)
> Vulnerable versions have been removed from the tree.

Indeed. Nothing to do for openoffice anymore
Comment 8 Chris Reffett (RETIRED) gentoo-dev Security 2013-10-21 23:59:20 UTC
GLSA vote: no.
Comment 9 Sergey Popov gentoo-dev 2013-11-13 09:08:42 UTC
GLSA vote: no

Closing as noglsa