Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 638334 - app-office/openoffice-bin: Multiple vulnerabilities
Summary: app-office/openoffice-bin: Multiple vulnerabilities
Status: RESOLVED DUPLICATE of bug 635120
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor
Assignee: Gentoo Security
URL:
Whiteboard: B3 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-11-21 16:29 UTC by GLSAMaker/CVETool Bot
Modified: 2017-11-21 16:42 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2017-11-21 16:29:14 UTC
CVE-2017-9806 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-9806):
  A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and
  specifically in the WW8Fonts Constructor, allows attackers to craft
  malicious documents that cause denial of service (memory corruption and
  application crash) potentially resulting in arbitrary code execution.

CVE-2017-3157 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-3157):
  By exploiting the way Apache OpenOffice before 4.1.4 renders embedded
  objects, an attacker could craft a document that allows reading in a file
  from the user's filesystem. Information could be retrieved by the attacker
  by, e.g., using hidden sections to store the information, tricking the user
  into saving the document and convincing the user to send the document back
  to the attacker. The vulnerability is mitigated by the need for the attacker
  to know the precise file path in the target system, and the need to trick
  the user into saving the document and sending it back.

CVE-2017-12608 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12608):
  A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4,
  and specifically in ImportOldFormatStyles, allows attackers to craft
  malicious documents that cause denial of service (memory corruption and
  application crash) potentially resulting in arbitrary code execution.

CVE-2017-12607 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12607):
  A vulnerability in OpenOffice's PPT file parser before 4.1.4, and
  specifically in PPTStyleSheet, allows attackers to craft malicious documents
  that cause denial of service (memory corruption and application crash)
  potentially resulting in arbitrary code execution.
Comment 1 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-11-21 16:42:33 UTC

*** This bug has been marked as a duplicate of bug 635120 ***