Lucene search

K
centosCentOS ProjectCESA-2012:0705
HistoryJun 05, 2012 - 10:03 a.m.

autocorr, broffice.org, openoffice.org security update

2012-06-0510:03:16
CentOS Project
lists.centos.org
56

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

High

0.047 Low

EPSS

Percentile

92.7%

CentOS Errata and Security Advisory CESA-2012:0705

OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet application,
presentation manager, formula editor, and a drawing program.

An integer overflow flaw, leading to a buffer overflow, was found in the
way OpenOffice.org processed an invalid Escher graphics records length in
Microsoft Office PowerPoint documents. An attacker could provide a
specially-crafted Microsoft Office PowerPoint document that, when opened,
would cause OpenOffice.org to crash or, potentially, execute arbitrary code
with the privileges of the user running OpenOffice.org. (CVE-2012-2334)

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in the JPEG, PNG, and BMP image file reader implementations in
OpenOffice.org. An attacker could provide a specially-crafted JPEG, PNG,
or BMP image file that, when opened in an OpenOffice.org application, would
cause the application to crash or, potentially, execute arbitrary code with
the privileges of the user running the application. (CVE-2012-1149)

Upstream acknowledges Sven Jacobi as the original reporter of
CVE-2012-2334, and Tielei Wang via Secunia SVCRP as the original reporter
of CVE-2012-1149.

All OpenOffice.org users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of OpenOffice.org applications must be restarted for this update
to take effect.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2012-June/080827.html
https://lists.centos.org/pipermail/centos-announce/2012-June/080828.html

Affected packages:
autocorr-af
autocorr-bg
autocorr-cs
autocorr-da
autocorr-de
autocorr-en
autocorr-es
autocorr-eu
autocorr-fa
autocorr-fi
autocorr-fr
autocorr-ga
autocorr-hu
autocorr-it
autocorr-ja
autocorr-ko
autocorr-lb
autocorr-lt
autocorr-mn
autocorr-nl
autocorr-pl
autocorr-pt
autocorr-ru
autocorr-sk
autocorr-sl
autocorr-sv
autocorr-tr
autocorr-vi
autocorr-zh
broffice.org-base
broffice.org-brand
broffice.org-calc
broffice.org-draw
broffice.org-impress
broffice.org-math
broffice.org-writer
openoffice.org-base
openoffice.org-base-core
openoffice.org-brand
openoffice.org-bsh
openoffice.org-calc
openoffice.org-calc-core
openoffice.org-core
openoffice.org-devel
openoffice.org-draw
openoffice.org-draw-core
openoffice.org-emailmerge
openoffice.org-graphicfilter
openoffice.org-headless
openoffice.org-impress
openoffice.org-impress-core
openoffice.org-javafilter
openoffice.org-langpack-af_ZA
openoffice.org-langpack-ar
openoffice.org-langpack-as_IN
openoffice.org-langpack-bg_BG
openoffice.org-langpack-bn
openoffice.org-langpack-ca_ES
openoffice.org-langpack-cs_CZ
openoffice.org-langpack-cy_GB
openoffice.org-langpack-da_DK
openoffice.org-langpack-de
openoffice.org-langpack-dz
openoffice.org-langpack-el_GR
openoffice.org-langpack-en
openoffice.org-langpack-es
openoffice.org-langpack-et_EE
openoffice.org-langpack-eu_ES
openoffice.org-langpack-fi_FI
openoffice.org-langpack-fr
openoffice.org-langpack-ga_IE
openoffice.org-langpack-gl_ES
openoffice.org-langpack-gu_IN
openoffice.org-langpack-he_IL
openoffice.org-langpack-hi_IN
openoffice.org-langpack-hr_HR
openoffice.org-langpack-hu_HU
openoffice.org-langpack-it
openoffice.org-langpack-ja_JP
openoffice.org-langpack-kn_IN
openoffice.org-langpack-ko_KR
openoffice.org-langpack-lt_LT
openoffice.org-langpack-mai_IN
openoffice.org-langpack-ml_IN
openoffice.org-langpack-mr_IN
openoffice.org-langpack-ms_MY
openoffice.org-langpack-nb_NO
openoffice.org-langpack-nl
openoffice.org-langpack-nn_NO
openoffice.org-langpack-nr_ZA
openoffice.org-langpack-nso_ZA
openoffice.org-langpack-or_IN
openoffice.org-langpack-pa
openoffice.org-langpack-pa_IN
openoffice.org-langpack-pl_PL
openoffice.org-langpack-pt_BR
openoffice.org-langpack-pt_PT
openoffice.org-langpack-ro
openoffice.org-langpack-ru
openoffice.org-langpack-sk_SK
openoffice.org-langpack-sl_SI
openoffice.org-langpack-sr
openoffice.org-langpack-sr_CS
openoffice.org-langpack-ss_ZA
openoffice.org-langpack-st_ZA
openoffice.org-langpack-sv
openoffice.org-langpack-ta_IN
openoffice.org-langpack-te_IN
openoffice.org-langpack-th_TH
openoffice.org-langpack-tn_ZA
openoffice.org-langpack-tr_TR
openoffice.org-langpack-ts_ZA
openoffice.org-langpack-uk
openoffice.org-langpack-ur
openoffice.org-langpack-ve_ZA
openoffice.org-langpack-xh_ZA
openoffice.org-langpack-zh_CN
openoffice.org-langpack-zh_TW
openoffice.org-langpack-zu_ZA
openoffice.org-math
openoffice.org-math-core
openoffice.org-ogltrans
openoffice.org-opensymbol-fonts
openoffice.org-pdfimport
openoffice.org-presentation-minimizer
openoffice.org-presenter-screen
openoffice.org-pyuno
openoffice.org-report-builder
openoffice.org-rhino
openoffice.org-sdk
openoffice.org-sdk-doc
openoffice.org-testtools
openoffice.org-ure
openoffice.org-wiki-publisher
openoffice.org-writer
openoffice.org-writer-core
openoffice.org-xsltfilter

Upstream details at:
https://access.redhat.com/errata/RHSA-2012:0705

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

High

0.047 Low

EPSS

Percentile

92.7%