Beste mensen,
Er zijn enkele veiligheids-problemen gerepareerd in LibreOffice.
Iedereen wordt geadviseerd om te vernieuwen naar een versie groter of
gelijk aan 5.2.5 of groter of gelijk aan 5.3.0.
Meer informatie hieronder.
vr. groet,
Cor
-------- Forwarded Message --------
Subject: [tdf-discuss] security related information, CVE-2016-10327,
CVE-2017-7856, CVE-2017-7870, CVE-2017-7882
Date: Fri, 21 Apr 2017 13:06:53 +0100
From: Caolán McNamara <caolanm@redhat.com>
To: discuss@documentfoundation.org
tl;dr:
All users are recommended to upgrade to LibreOffice >= 5.2.5
or >= 5.3.0.
Recently 4 CVEs were filed for LibreOffice, namely...
CVE-2016-10327 Heap-buffer-overflow in EMF filter
CVE-2017-7856 Heap-buffer-overflow in WMF filter
CVE-2017-7882 Heap-buffer-overflow in HWP filter
CVE-2017-7870 Heap-buffer-overflow in WMF filter polygon processing
They are all related to the google oss-fuzz program (https://testing.go
ogleblog.com/2016/12/announcing-oss-fuzz-continuous-fuzzing.html) of
which we are part
These two:
CVE-2017-7856 Heap-buffer-overflow in WMF filter
CVE-2017-7882 Heap-buffer-overflow in HWP filter
refer to temporary defects which were introduced during the development
cycle and then fixed again before any release was made, so there is no
release affected by these specific issues.
These two however *are* in released products:
https://www.libreoffice.org/about-us/security/advisories/CVE-2016-10327
CVE-2016-10327 Heap-buffer-overflow in EMF filter
Enhanced Metafiles (EMF) can contain bitmap data preceded by a header
and a field with in that header which states the offset from the start
of the header to the bitmap data. An emf can be crafted to provide an
illegal offset which if not tested for validity can trigger a heap
buffer overflow.
https://www.libreoffice.org/about-us/security/advisories/CVE-2017-7870
CVE-2017-7870 Heap-buffer-overflow in WMF filter polygon processing
Windows Metafiles (WMF) can contain polygons which under certain
circumstances when processed (split) can result in output polygons
which have too many points to be represented by LibreOffice's internal
polygon class. resulting in a heap buffer overflow could occur as the
attempt to split the polygon was assumed to succeed.
Everything is fixed in 5.2.5 and 5.3.0
--
Unsubscribe instructions: E-mail to discuss+unsubscribe@nl.libreoffice.org
Posting guidelines + more: http://wiki.documentfoundation.org/Netiquette
List archive: http://listarchives.libreoffice.org/nl/discuss/
All messages sent to this list will be publicly archived and cannot be deleted
Context
- [nl-discuss] Fwd: security related information, CVE-2016-10327, CVE-2017-7856, CVE-2017-7870, CVE-2017-7882 · Cor Nouws
Privacy Policy |
Impressum (Legal Info) |
Copyright information: Unless otherwise specified, all text and images
on this website are licensed under the
Creative Commons Attribution-Share Alike 3.0 License.
This does not include the source code of LibreOffice, which is
licensed under the Mozilla Public License (
MPLv2).
"LibreOffice" and "The Document Foundation" are
registered trademarks of their corresponding registered owners or are
in actual use as trademarks in one or more countries. Their respective
logos and icons are also subject to international copyright laws. Use
thereof is explained in our
trademark policy.