Date: prev next · Thread: first prev next last


Beste mensen,

Er zijn enkele veiligheids-problemen gerepareerd in LibreOffice.
Iedereen wordt geadviseerd om te vernieuwen naar een versie groter of
gelijk aan 5.2.5 of groter of gelijk aan 5.3.0.

Meer informatie hieronder.

vr. groet,
Cor


-------- Forwarded Message --------
Subject: [tdf-discuss] security related information, CVE-2016-10327,
CVE-2017-7856, CVE-2017-7870, CVE-2017-7882
Date: Fri, 21 Apr 2017 13:06:53 +0100
From: Caolán McNamara <caolanm@redhat.com>
To: discuss@documentfoundation.org

tl;dr:
  All users are recommended to upgrade to LibreOffice >= 5.2.5
  or >= 5.3.0.

Recently 4 CVEs were filed for LibreOffice, namely...

CVE-2016-10327 Heap-buffer-overflow in EMF filter
CVE-2017-7856  Heap-buffer-overflow in WMF filter
CVE-2017-7882  Heap-buffer-overflow in HWP filter
CVE-2017-7870  Heap-buffer-overflow in WMF filter polygon processing

They are all related to the google oss-fuzz program (https://testing.go
ogleblog.com/2016/12/announcing-oss-fuzz-continuous-fuzzing.html) of
which we are part

These two:

CVE-2017-7856  Heap-buffer-overflow in WMF filter
CVE-2017-7882  Heap-buffer-overflow in HWP filter

refer to temporary defects which were introduced during the development
cycle and then fixed again before any release was made, so there is no
release affected by these specific issues.


These two however *are* in released products:

https://www.libreoffice.org/about-us/security/advisories/CVE-2016-10327
CVE-2016-10327 Heap-buffer-overflow in EMF filter

Enhanced Metafiles (EMF) can contain bitmap data preceded by a header
and a field with in that header which states the offset from the start
of the header to the bitmap data. An emf can be crafted to provide an
illegal offset which if not tested for validity can trigger a heap
buffer overflow.

https://www.libreoffice.org/about-us/security/advisories/CVE-2017-7870
CVE-2017-7870  Heap-buffer-overflow in WMF filter polygon processing

Windows Metafiles (WMF) can contain polygons which under certain
circumstances when processed (split) can result in output polygons
which have too many points to be represented by LibreOffice's internal
polygon class. resulting in a heap buffer overflow could occur as the
attempt to split the polygon was assumed to succeed.

Everything is fixed in 5.2.5 and 5.3.0


-- 
Unsubscribe instructions: E-mail to discuss+unsubscribe@nl.libreoffice.org
Posting guidelines + more: http://wiki.documentfoundation.org/Netiquette
List archive: http://listarchives.libreoffice.org/nl/discuss/
All messages sent to this list will be publicly archived and cannot be deleted

Context


Privacy Policy | Impressum (Legal Info) | Copyright information: Unless otherwise specified, all text and images on this website are licensed under the Creative Commons Attribution-Share Alike 3.0 License. This does not include the source code of LibreOffice, which is licensed under the Mozilla Public License (MPLv2). "LibreOffice" and "The Document Foundation" are registered trademarks of their corresponding registered owners or are in actual use as trademarks in one or more countries. Their respective logos and icons are also subject to international copyright laws. Use thereof is explained in our trademark policy.