Bug 62730 (CVE-2004-0889)

Summary: VUL-0: CVE-2004-0889: KOffice: include vulnerable xpdf code
Product: [Novell Products] SUSE Security Incidents Reporter: Thomas Biege <thomas>
Component: IncidentsAssignee: Adrian Schröter <adrian.schroeter>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: kde-maintainers, patch-request, security-team
Version: unspecified   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: CVE-2004-0889: CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C) CVSSv2:NVD:CVE-2004-0888:10.0:(AV:N/AC:L/Au:N/C:C/I:C/A:C) CVSSv2:RedHat:CVE-2004-0888:5.8:(AV:A/AC:L/Au:N/C:P/I:P/A:P)
Found By: Other Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---
Bug Depends on: 64840    
Bug Blocks:    
Attachments: patchinfo-box.koffice
patchinfo.koffice

Description Thomas Biege 2004-10-28 17:38:55 UTC
Hi, 
the Gentoo folks say that KOffice include the vulnerable xpdf code (like the 
last kpdf/kdegraphics3-pdf update).
Comment 1 Thomas Biege 2004-10-28 17:38:55 UTC
<!-- SBZ_reproduce  -->
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 
Gentoo Linux Security Advisory                           GLSA 200410-30 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 
                                            http://security.gentoo.org/ 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 
 
  Severity: Normal 
     Title: GPdf, KPDF, KOffice: Vulnerabilities in included xpdf 
      Date: October 28, 2004 
      Bugs: #68558, #68665, #68571 
        ID: 200410-30 
 
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 
 
Synopsis 
======== 
 
GPdf, KPDF and KOffice all include vulnerable xpdf code to handle PDF 
files, making them vulnerable to execution of arbitrary code upon 
viewing a malicious PDF file. 
 
Background 
========== 
 
GPdf is a Gnome-based PDF viewer. KPDF, part of the kdegraphics 
package, is a KDE-based PDF viewer. KOffice is an integrated office 
suite for KDE.
Comment 2 Adrian Schröter 2004-11-10 17:06:32 UTC
koffice is maintained by Lukas 
Comment 3 Lukas Tinkl 2004-11-10 20:21:19 UTC
KOffice 1.3.4 was supposed to fix this ... but failed :( There's currently a new
patch available, Thomas please review it.

See http://kde.org/areas/koffice/releases/1.3.4-release.php
Comment 4 Lukas Tinkl 2004-11-10 20:25:00 UTC
Hmm, the redirection scripts on download.kde.org don't seem to work, here's a
direct link: ftp://ftp.kde.org/pub/kde/stable/koffice-1.3.4/src/patch/
Comment 5 Thomas Biege 2004-11-15 17:00:14 UTC
Sorry, I was on vacation. 
 
The fix looks incomplete. 
 
Please have a look at bug 58082 comment #50 
Comment 6 Lukas Tinkl 2004-12-06 02:30:12 UTC
I'll check if KOffice 1.3.5 contains the right fix
Comment 7 Thomas Biege 2004-12-14 19:44:46 UTC
Hi Lukas, 
is there something you found out yet? 
Comment 8 Lukas Tinkl 2004-12-16 19:23:53 UTC
It seems it is the right fix in KOffice 1.3.5; if in doubt please check for
yourself too :)
Comment 9 Marcus Meissner 2004-12-16 20:06:13 UTC
and now the euro 100 question ... can you provide updated packages  
for older suse versions? :) 
Comment 10 Lukas Tinkl 2004-12-29 19:00:11 UTC
Raising the bar to 200 Euro, just another xpdf vulnerability appeared:

http://kde.org/areas/koffice/releases/1.3.5-release.php

On Jan 3, I'll be back from vacation, update koffice and backport.
Comment 11 Lukas Tinkl 2005-01-07 02:28:25 UTC
Committed a fix to STABLE, working on 9.2 backport
Comment 12 Lukas Tinkl 2005-01-07 05:30:33 UTC
Backported to 9.2 
Comment 13 Ludwig Nussel 2005-01-18 19:27:57 UTC
we also need the fix for #49840 
Comment 14 Lukas Tinkl 2005-01-20 18:38:02 UTC
OK, it's been already applied to KOffice's CVS, will take it
Comment 16 Thomas Biege 2005-01-25 21:31:03 UTC
CAN-2004-0888, CAN-2004-0889, CAN-2004-1125, CAN-2005-0064 
Comment 17 Thomas Biege 2005-01-25 21:33:55 UTC
 SM-Tracker-221 
Comment 18 Thomas Biege 2005-01-25 21:56:42 UTC
Created attachment 27906 [details]
patchinfo-box.koffice
Comment 19 Thomas Biege 2005-01-25 21:57:02 UTC
Created attachment 27907 [details]
patchinfo.koffice
Comment 20 Thomas Biege 2005-02-14 22:05:50 UTC
Lukas, 
when can we expect the new packages? 
Comment 21 Lukas Tinkl 2005-02-15 17:45:55 UTC
Working on it, took some more time due to KOffice not compiling and other duties.
Comment 22 Thomas Biege 2005-02-15 18:22:35 UTC
We are far behind other distributors with releasing koffice now. 
Some bugs are older then 4 month now. :( 
 
Do you see a possibility to speed this update up? 
Comment 23 Lukas Tinkl 2005-02-15 18:55:00 UTC
Yes, I could commit without test-compiling but my old poor 500Mhz Intel III
can't work any faster than this... :(
Comment 24 Thomas Biege 2005-02-15 19:55:29 UTC
Can't you use faster machine in the suse network? 
Comment 25 Lukas Tinkl 2005-02-16 19:58:56 UTC
Fixed package submitted to STABLE, backport?
Comment 26 Ludwig Nussel 2005-02-16 20:44:59 UTC
Yes of course. 
Comment 27 Thomas Biege 2005-02-24 10:53:15 UTC
Lukas, 
do you need some help doing the updates? We are far far behind other vendors. 
Comment 28 Adrian Schröter 2005-03-01 10:33:59 UTC
packages are submitted now. 
Comment 29 Marcus Meissner 2005-03-01 12:34:13 UTC
submitted patchinfos (corrected). 
Comment 30 Ludwig Nussel 2005-03-03 13:46:05 UTC
There are patches missing. koffice has xpdf2 which has more than two security 
patches applied. According to xpdf2 from 8.2 you may need all of the following 
patches. At least the libgoo patch is definitely missing from the koffice 
package: 
 
xpdf-2.01-overflow.patch 
xpdf-CESA-2004-007-xpdf2.diff 
xpdf2-underflow.diff 
libgoo-sizet.diff 
xpdf-3.00pl2.patch 
xpdf-3.00pl3.patch 
Comment 31 Marcus Meissner 2005-03-09 12:13:47 UTC
adrian did the koffice updates... 
Comment 32 Marcus Meissner 2005-03-14 12:45:08 UTC
just add it to the next xpdf update. 
 
updates released. 
Comment 33 Thomas Biege 2009-10-13 19:55:56 UTC
CVE-2004-0889: CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)