[openoffice.org] [CVE-2007-4575] Potential arbitrary code execution vulnerability in 3rd party module (HSQLDB)

Bug #174112 reported by disabled.user
264
Affects Status Importance Assigned to Milestone
hsqldb (Gentoo Linux)
Fix Released
Medium
openoffice.org (Gentoo Linux)
Fix Released
High
openoffice.org (Ubuntu)
Fix Released
Critical
Unassigned
Dapper
Fix Released
Critical
Kees Cook
Edgy
Won't Fix
Critical
Kees Cook
Feisty
Fix Released
Critical
Kees Cook
Gutsy
Fix Released
Critical
Kees Cook

Bug Description

Binary package hint: openoffice.org

References:
http://www.openoffice.org/security/cves/CVE-2007-4575.html

Quoting:
"A security vulnerability in HSQLDB, the default database engine shipped with OpenOffice.org 2 (all versions), may allow attackers to execute arbitrary static Java code, by manipulating database documents to be opened by a user."

CVE References

Colin Watson (cjwatson)
Changed in openoffice.org:
assignee: nobody → ccheney
importance: Undecided → Critical
status: New → Confirmed
Revision history for this message
Chris Cheney (ccheney) wrote :

I'm sorry I didn't respond to this bug earlier. I am working with the hsqldb author on a fix that won't require any changes to the openoffice.org codebase which allows us to not have to push as much data out. Hopefully this will be rolled out by the end of the week.

Thanks,

Chris Cheney

Revision history for this message
NoOp (glgxg) wrote :

Can the Debian fixes not be used?

http://www.debian.org/security/2007/dsa-1419

Revision history for this message
Chris Cheney (ccheney) wrote :

The Debian fix is for one particular version of hsqldb and openoffice so no they won't work as is since Debian and Ubuntu release cycles aren't in sync. I should have a patch from upstream within the next couple days.

Thanks,

Chris Cheney

Chris Cheney (ccheney)
Changed in openoffice.org:
status: Confirmed → In Progress
Changed in hsqldb:
status: Unknown → Fix Released
Changed in openoffice.org:
status: Unknown → Fix Released
Chris Cheney (ccheney)
Changed in openoffice.org:
assignee: ccheney → nobody
status: In Progress → Fix Released
assignee: nobody → ccheney
importance: Undecided → Critical
status: New → In Progress
assignee: nobody → ccheney
importance: Undecided → Critical
status: New → In Progress
assignee: nobody → ccheney
importance: Undecided → Critical
status: New → In Progress
assignee: nobody → ccheney
importance: Undecided → Critical
status: New → In Progress
Revision history for this message
Chris Cheney (ccheney) wrote :

I believe that this CVE along with the newer one will be fixed in a security announcement early next week. It appears the security team is being held up by some infrastructure work.

Revision history for this message
disabled.user (disabled.user-deactivatedaccount) wrote :

There's still no fix for this available as of now.

Revision history for this message
Kees Cook (kees) wrote : Re: [Bug 174112] Re: [openoffice.org] [CVE-2007-4575] Potential arbitrary code execution vulnerability in 3rd party module (HSQLDB)

On Tue, May 06, 2008 at 09:42:45AM -0000, hk47 wrote:
> There's still no fix for this available as of now.

It's almost done -- there is a lot of churn after the release.
Hopefully it will publish today.

Revision history for this message
Kees Cook (kees) wrote :

This has been addressed by USN: http://www.ubuntu.com/usn/usn-609-1

Changed in openoffice.org:
assignee: ccheney → keescook
status: In Progress → Won't Fix
assignee: ccheney → keescook
status: In Progress → Fix Released
assignee: ccheney → keescook
status: In Progress → Fix Released
assignee: ccheney → keescook
status: In Progress → Fix Released
Changed in openoffice.org (Gentoo Linux):
importance: Unknown → High
Changed in hsqldb (Gentoo Linux):
importance: Unknown → Medium
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.