Bug 987553 (CVE-2016-4324) - VUL-1: CVE-2016-4324 libreoffice: Dereference of invalid STL iterator on processing RTF file
Summary: VUL-1: CVE-2016-4324 libreoffice: Dereference of invalid STL iterator on proc...
Status: RESOLVED FIXED
Alias: CVE-2016-4324
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Major
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/170561/
Whiteboard: CVSSv2:SUSE:CVE-2016-4324:6.8:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-07-04 12:15 UTC by Andreas Stieger
Modified: 2017-08-01 14:37 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2016-07-04 12:15:24 UTC
https://www.libreoffice.org/about-us/security/advisories/cve-2016-4324/
Fixed in: LibreOffice 5.1.4/5.2.0

Parsing the Rich Text Format character style index was insufficiently checked for validity. Documents can be constructed which dereference an iterator to the first entry of an empty STL container.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1351197
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4324
http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-4324.html
http://www.debian.org/security/2016/dsa-3608
http://blog.talosintel.com/2016/06/vulnerability-spotlight-libreoffice-rtf.html
Comment 3 Bernhard Wiedemann 2016-07-04 14:00:53 UTC
This is an autogenerated message for OBS integration:
This bug (987553) was mentioned in
https://build.opensuse.org/request/show/406393 Factory / libreoffice
Comment 5 Swamp Workflow Management 2016-07-04 22:00:50 UTC
bugbot adjusting priority
Comment 8 Swamp Workflow Management 2016-10-06 20:09:50 UTC
SUSE-SU-2016:2472-1: An update that solves one vulnerability and has one errata is now available.

Category: security (low)
Bug References: 1000102,987553
CVE References: CVE-2016-4324
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP1 (src):    libreoffice-5.1.5.2-29.4
SUSE Linux Enterprise Desktop 12-SP1 (src):    libreoffice-5.1.5.2-29.4
Comment 9 Andreas Stieger 2016-10-14 10:11:21 UTC
Is this fixable for 13.2?
Comment 10 Tomáš Chvátal 2016-10-14 10:20:14 UTC
(In reply to Andreas Stieger from comment #9)
> Is this fixable for 13.2?

Yes and no. As there were more issues and it is quite effort to update to 5.1 series libreoffice there. ECO update covers Leap. I asked community to do it. 2 people said they will, nobody ever followed upon it...

If you want just this patch tho it is just 4 lines and it indeed is doable.
Comment 11 Swamp Workflow Management 2016-10-14 13:12:02 UTC
openSUSE-SU-2016:2538-1: An update that solves one vulnerability and has one errata is now available.

Category: security (low)
Bug References: 1000102,987553
CVE References: CVE-2016-4324
Sources used:
openSUSE Leap 42.1 (src):    libreoffice-5.1.5.2-11.1
Comment 12 Tomáš Chvátal 2017-05-16 10:50:00 UTC
13.2 out of support scope.