Home page logo

oss-sec logo oss-sec mailing list archives

Re: CVE-2012-4233: multiple null pointer dereference flaws in LibreOffice/OpenOffice.org
From: Caolán McNamara <caolanm () redhat com>
Date: Fri, 02 Nov 2012 09:38:58 +0000

On Fri, 2012-11-02 at 09:07 +0100, Marcus Meissner wrote:
On Thu, Nov 01, 2012 at 02:44:23PM -0600, Vincent Danen wrote:
This one took me a bit by surprise.  Debian released an advisory for OOo
and I have no record of this CVE anywhere.  It looks as though it went
public yesterday, and was fixed in upstream, but it's not noted
on the LibreOffice web site at all.

Because I update the web site and I didn't get around to it until this
morning. http://www.libreoffice.org/advisories/cve-2012-4233/
https://www.htbridge.com/advisory/HTB23106 is the source of the CVE and
their advisory contains the reproducer documents.

Does anyone have any further details on these issues?  I just filed a
bug in our bugzilla (https://bugzilla.redhat.com/show_bug.cgi?id=872350)
with the following description/references which are all I've been able
to find so far.

These are the commits for the high-tech advisories

(The whole OpenOffice/LibreOffice security issue handling is not really
good ... long embargoes that get extended wildly even though fixes are in
public GIT already, etc )

Well, I'd be more than happy to have more distro folk subscribed to
officesecurity () lists freedesktop org Fixing the bugs is easy, syncing
embargo dates between LibreOffice and Apache OOo is a bit more


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]