libwpd: CVE-2017-14226

Related Vulnerabilities: CVE-2017-14226  

Debian Bug report logs - #876001
libwpd: CVE-2017-14226

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Sun, 17 Sep 2017 08:51:01 UTC

Severity: important

Tags: patch, security, upstream

Found in versions libwpd/0.10.1-5, libwpd/0.10.0-2

Fixed in versions libwpd/0.10.1-5+deb9u1, libwpd/0.10.0-2+deb8u1, libwpd/0.10.2-1

Done: Rene Engelhard <rene@debian.org>

Bug is archived. No further changes may be made.

Forwarded to https://sourceforge.net/p/libwpd/tickets/14/

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>:
Bug#876001; Package src:libwpd. (Sun, 17 Sep 2017 08:51:04 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>. (Sun, 17 Sep 2017 08:51:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: libwpd: CVE-2017-14226
Date: Sun, 17 Sep 2017 10:47:06 +0200
Source: libwpd
Version: 0.10.1-5
Severity: important
Tags: patch security upstream
Forwarded: https://sourceforge.net/p/libwpd/tickets/14/

Hi,

the following vulnerability was published for libwpd.

CVE-2017-14226[0]:
| WP1StylesListener.cpp, WP5StylesListener.cpp, and
| WP42StylesListener.cpp in libwpd 0.10.1 mishandle iterators, which
| allows remote attackers to cause a denial of service (heap-based buffer
| over-read in the WPXTableList class in WPXTable.cpp). This
| vulnerability can be triggered in LibreOffice before 5.3.7. It may lead
| to suffering a remote attack against a LibreOffice application.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-14226
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14226
[1] https://sourceforge.net/p/libwpd/tickets/14/
[2] https://bugzilla.redhat.com/show_bug.cgi?id=1489337
[3] https://cgit.freedesktop.org/libreoffice/core/commit/?id=dd89afa6ee8166b69e7a1e86f22616ca8fc122c9
[4] https://sourceforge.net/p/libwpd/code/ci/0329a9c57f9b3b0efa0f09a5235dfd90236803a5/
[5] https://sourceforge.net/p/libwpd/code/ci/f40827b3eae260ce657c67d9fecc855b09dea3c3/
[6] https://bugs.documentfoundation.org/show_bug.cgi?id=112269

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



Marked as found in versions libwpd/0.10.0-2. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sun, 17 Sep 2017 09:06:03 GMT) (full text, mbox, link).


Added tag(s) pending. Request was from Rene Engelhard <rene@rene-engelhard.de> to control@bugs.debian.org. (Sun, 17 Sep 2017 09:39:13 GMT) (full text, mbox, link).


Message sent on to Salvatore Bonaccorso <carnil@debian.org>:
Bug#876001. (Sun, 17 Sep 2017 09:39:16 GMT) (full text, mbox, link).


Message #12 received at 876001-submitter@bugs.debian.org (full text, mbox, reply):

From: Rene Engelhard <rene@rene-engelhard.de>
To: 876001-submitter@bugs.debian.org
Subject: Bug#876001 marked as pending
Date: Sun, 17 Sep 2017 09:37:09 +0000
tag 876001 pending
thanks

Hello,

Bug #876001 reported by you has been fixed in the Git repository. You can
see the changelog below, and you can check the diff of the fix at:

    https://anonscm.debian.org/cgit/pkg-openoffice/libwpd.git/commit/?id=5fd7928

---
commit 5fd7928705c096d9c61e540636dc3e5bfd2f7c15
Author: Rene Engelhard <rene@rene-engelhard.de>
Date:   Sun Sep 17 09:32:45 2017 +0000

    update changelog

diff --git a/debian/changelog b/debian/changelog
index 1da67fc..67fcc00 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,10 @@
+libwpd (0.10.2-1) unstable; urgency=medium
+
+  * New upstream version 0.10.2
+    - fixes CVE-2017-14226 (closes: #876001)
+
+ -- Rene Engelhard <rene@debian.org>  Sun, 17 Sep 2017 11:31:28 +0200
+
 libwpd (0.10.1-5) unstable; urgency=medium
 
   * [7d35591] move Maintainer: to Debian LibreOffice Maintainers



Reply sent to Rene Engelhard <rene@debian.org>:
You have taken responsibility. (Sun, 17 Sep 2017 09:54:03 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Sun, 17 Sep 2017 09:54:03 GMT) (full text, mbox, link).


Message #17 received at 876001-close@bugs.debian.org (full text, mbox, reply):

From: Rene Engelhard <rene@debian.org>
To: 876001-close@bugs.debian.org
Subject: Bug#876001: fixed in libwpd 0.10.2-1
Date: Sun, 17 Sep 2017 09:50:14 +0000
Source: libwpd
Source-Version: 0.10.2-1

We believe that the bug you reported is fixed in the latest version of
libwpd, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 876001@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Rene Engelhard <rene@debian.org> (supplier of updated libwpd package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sun, 17 Sep 2017 11:31:28 +0200
Source: libwpd
Binary: libwpd-dev libwpd-0.10-10 libwpd-tools libwpd-doc
Architecture: source
Version: 0.10.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>
Changed-By: Rene Engelhard <rene@debian.org>
Description:
 libwpd-0.10-10 - Library for handling WordPerfect documents (shared library)
 libwpd-dev - Library for handling WordPerfect documents (development)
 libwpd-doc - Library for handling WordPerfect documents (documentation)
 libwpd-tools - Tools from libwpd for converting WordPerfect to HTML/RAW/Text
Closes: 876001
Changes:
 libwpd (0.10.2-1) unstable; urgency=medium
 .
   * New upstream version 0.10.2
     - fixes CVE-2017-14226 (closes: #876001)
Checksums-Sha1:
 898c4e10fc594cf858c68e17e1a89d2387d7b7cf 2038 libwpd_0.10.2-1.dsc
 a6ea89f82c44df889cc5718608c4bfd6740eeb34 674231 libwpd_0.10.2.orig.tar.bz2
 a95d6c47cbf4880662cfba1c5fa04c4024493754 11424 libwpd_0.10.2-1.debian.tar.xz
 f4ba3b30cea80c2c9314f6c2124d3f335abff56f 5246 libwpd_0.10.2-1_source.buildinfo
Checksums-Sha256:
 07c8c0539871f3f915341e793326cf3289ebd3e2848e8996dd21d00df26001bf 2038 libwpd_0.10.2-1.dsc
 8859deb6df292c82c7657b7ecbb6f3ef65da252df9d265b755f06bec77add52c 674231 libwpd_0.10.2.orig.tar.bz2
 46fcf7006451f7b002734e8092cd93a8c4d4f56760244d70553cc8bfae0fa86d 11424 libwpd_0.10.2-1.debian.tar.xz
 0778f4cf99506189de904650be5ea71d4b1efa95c209999938700fda66481e78 5246 libwpd_0.10.2-1_source.buildinfo
Files:
 dd03066e70e47a94a015030a887a43e8 2038 devel optional libwpd_0.10.2-1.dsc
 c70d93efa6819b11310ccc5ec8e3821c 674231 devel optional libwpd_0.10.2.orig.tar.bz2
 473c907fd94e7f436f662082e06ff66f 11424 devel optional libwpd_0.10.2-1.debian.tar.xz
 f4e11b2b9e2bffeb6d28de7c85dbd53b 5246 devel optional libwpd_0.10.2-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE4S3qRnUGcM+pYIAdCqBFcdA+PnAFAlm+QiYACgkQCqBFcdA+
PnBx4Q//aL+tP7wOxRGy4ao253QHydxKV+X8iELIHVpAe3Lwg4Ln4s8Tzl6CMKvX
5oATDyzhpKymFnD3jRJnJCUsVPyqQDVgUPgJcyorok7atzADzs2RJBoSvZODylQz
hV4t3msOTTR7PX8jRP9vjjYWzYKWLU6ZU4WQT4jBQkTGj/k3DB/6Whd598gI+X+I
7saf27OCnrMnBYVSaSMIx43YsPrzx4pSsZAYCuL6dfI0JEYm3MEl+djgsk3rP8/A
0rbjdlPoJ54q5ofzIUt7tkWuXrW5tf+VoliEQHvON2f2mQ/Esg5SVhhZSNTIH2RM
j5WSNgqMRl/P7hM+gh4LIetQ42TmG5k59/VsLbBChRvOaCM6eOQ+r/417UQXavbC
KkS4uBB9TXLwFnLAObh4Sx+2bnysznIg9RLEatpTbPHTF4QxtqxR/Na4+VCZg3xz
EHOnCJIdvakXKPlH1bzjl1B2eNZ2e3x7XN7R38syOqEpqpPf72IZ4xp+2gcMGtiq
bThVuag5Mn4tEP0pBGnAtrOH9lLT8znsYitI/izbfrKUlbLT889t+6goGdlil4Lm
ChvOnEr0g/ca2K2sDcaahRAF+yC1KUUNO43HXEh4CEch8T1y74UZnZi6YPWCVI9P
CgKEEN2vRHGbzKqEi24OAHwBScuvZCLeH74nMGLcnyc+QABLH7Q=
=rJWo
-----END PGP SIGNATURE-----




Information forwarded to debian-bugs-dist@lists.debian.org, Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>:
Bug#876001; Package src:libwpd. (Sun, 17 Sep 2017 09:57:02 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>. (Sun, 17 Sep 2017 09:57:03 GMT) (full text, mbox, link).


Message #22 received at 876001@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: 876001@bugs.debian.org
Subject: CVE-2017-14226
Date: Sun, 17 Sep 2017 11:54:01 +0200
[Message part 1 (text/plain, inline)]
for reference respective traces:

0.10.1-5:

ASAN:DEADLYSIGNAL
=================================================================
==19356==ERROR: AddressSanitizer: SEGV on unknown address 0x55959d2ac260 (pc 0x55959d04d55f bp 0x7ffcf9f1c3c0 sp 0x7ffcf9f1c368 T0)
==19356==The signal is caused by a WRITE memory access.
    #0 0x55959d04d55e in WPXTableList::WPXTableList(WPXTableList const&) /root/libwpd-0.10.1/src/lib/WPXTable.cpp:169
    #1 0x55959d043484 in WPXHeaderFooter::getTableList() const /root/libwpd-0.10.1/src/lib/WPXPageSpan.h:66
    #2 0x55959d043484 in WP5StylesListener::insertBreak(unsigned char) /root/libwpd-0.10.1/src/lib/WP5StylesListener.cpp:94
    #3 0x55959d0414f3 in WP5Parser::parseDocument(librevenge::RVNGInputStream*, WPXEncryption*, WP5Listener*) /root/libwpd-0.10.1/src/lib/WP5Parser.cpp:102
    #4 0x55959d04162f in WP5Parser::parseSubDocument(librevenge::RVNGTextInterface*) /root/libwpd-0.10.1/src/lib/WP5Parser.cpp:234
    #5 0x55959d037c2a in libwpd::WPDocument::parseSubDocument(librevenge::RVNGInputStream*, librevenge::RVNGTextInterface*, libwpd::WPDFileFormat) /root/libwpd-0.10.1/src/lib/WPDocument.cpp:460
    #6 0x55959d053637 in WP3ContentListener::insertWP51Table(double, double, double, double, unsigned char, unsigned char, unsigned short, WP3SubDocument const*, WP3SubDocument const*) /root/libwpd-0.10.1/src/lib/WP3ContentListener.cpp:867
    #7 0x55959d03f45b in WP3WindowGroup::parse(WP3Listener*) /root/libwpd-0.10.1/src/lib/WP3WindowGroup.cpp:144
    #8 0x55959d03c431 in WP3Parser::parseDocument(librevenge::RVNGInputStream*, WPXEncryption*, WP3Listener*) /root/libwpd-0.10.1/src/lib/WP3Parser.cpp:107
    #9 0x55959d03c492 in WP3Parser::parse(librevenge::RVNGInputStream*, WPXEncryption*, WP3Listener*) /root/libwpd-0.10.1/src/lib/WP3Parser.cpp:76
    #10 0x55959d03c887 in WP3Parser::parse(librevenge::RVNGTextInterface*) /root/libwpd-0.10.1/src/lib/WP3Parser.cpp:153
    #11 0x55959d037ead in libwpd::WPDocument::parse(librevenge::RVNGInputStream*, librevenge::RVNGTextInterface*, char const*) /root/libwpd-0.10.1/src/lib/WPDocument.cpp:345
    #12 0x55959d037560 in main /root/libwpd-0.10.1/src/conv/html/wpd2html.cpp:116
    #13 0x7f0b7533d2e0 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x202e0)
    #14 0x55959d037719 in _start (/root/libwpd-0.10.1/src/conv/html/wpd2html+0x10719)

AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV /root/libwpd-0.10.1/src/lib/WPXTable.cpp:169 in WPXTableList::WPXTableList(WPXTableList const&)
==19356==ABORTING

0.10.0-2:

ASAN:DEADLYSIGNAL
=================================================================
==19364==ERROR: AddressSanitizer: SEGV on unknown address 0x563045443b58 (pc 0x5630451e51c3 bp 0x7ffe20d01590 sp 0x7ffe20d01538 T0)
==19364==The signal is caused by a WRITE memory access.
    #0 0x5630451e51c2 in WPXTableList::WPXTableList(WPXTableList const&) /root/source-libwpd/libwpd-0.10.0/src/lib/WPXTable.cpp:169
    #1 0x5630451db304 in WPXHeaderFooter::getTableList() const /root/source-libwpd/libwpd-0.10.0/src/lib/WPXPageSpan.h:66
    #2 0x5630451db304 in WP5StylesListener::insertBreak(unsigned char) /root/source-libwpd/libwpd-0.10.0/src/lib/WP5StylesListener.cpp:94
    #3 0x5630451d9583 in WP5Parser::parseDocument(librevenge::RVNGInputStream*, WPXEncryption*, WP5Listener*) /root/source-libwpd/libwpd-0.10.0/src/lib/WP5Parser.cpp:102
    #4 0x5630451d96bf in WP5Parser::parseSubDocument(librevenge::RVNGTextInterface*) /root/source-libwpd/libwpd-0.10.0/src/lib/WP5Parser.cpp:234
    #5 0x5630451cfc72 in libwpd::WPDocument::parseSubDocument(librevenge::RVNGInputStream*, librevenge::RVNGTextInterface*, libwpd::WPDFileFormat) /root/source-libwpd/libwpd-0.10.0/src/lib/WPDocument.cpp:452
    #6 0x5630451eb317 in WP3ContentListener::insertWP51Table(double, double, double, double, unsigned char, unsigned char, unsigned short, WP3SubDocument const*, WP3SubDocument const*) /root/source-libwpd/libwpd-0.10.0/src/lib/WP3ContentListener.cpp:867
    #7 0x5630451d74db in WP3WindowGroup::parse(WP3Listener*) /root/source-libwpd/libwpd-0.10.0/src/lib/WP3WindowGroup.cpp:144
    #8 0x5630451d4491 in WP3Parser::parseDocument(librevenge::RVNGInputStream*, WPXEncryption*, WP3Listener*) /root/source-libwpd/libwpd-0.10.0/src/lib/WP3Parser.cpp:107
    #9 0x5630451d44f2 in WP3Parser::parse(librevenge::RVNGInputStream*, WPXEncryption*, WP3Listener*) /root/source-libwpd/libwpd-0.10.0/src/lib/WP3Parser.cpp:76
    #10 0x5630451d48e7 in WP3Parser::parse(librevenge::RVNGTextInterface*) /root/source-libwpd/libwpd-0.10.0/src/lib/WP3Parser.cpp:153
    #11 0x5630451cfefd in libwpd::WPDocument::parse(librevenge::RVNGInputStream*, librevenge::RVNGTextInterface*, char const*) /root/source-libwpd/libwpd-0.10.0/src/lib/WPDocument.cpp:340
    #12 0x5630451cf600 in main /root/source-libwpd/libwpd-0.10.0/src/conv/html/wpd2html.cpp:112
    #13 0x7f757c8b32e0 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x202e0)
    #14 0x5630451cf7b9 in _start (/root/source-libwpd/libwpd-0.10.0/src/conv/html/wpd2html+0x107b9)

AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV /root/source-libwpd/libwpd-0.10.0/src/lib/WPXTable.cpp:169 in WPXTableList::WPXTableList(WPXTableList const&)
==19364==ABORTING

attaching the reproducer file in case https://bugzilla.redhat.com/show_bug.cgi?id=1489337 disappers.

Regards,
Salvatore
[poc.xz (application/x-xz, attachment)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>:
Bug#876001; Package src:libwpd. (Sun, 17 Sep 2017 12:09:06 GMT) (full text, mbox, link).


Acknowledgement sent to Rene Engelhard <rene@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>. (Sun, 17 Sep 2017 12:09:06 GMT) (full text, mbox, link).


Message #27 received at 876001@bugs.debian.org (full text, mbox, reply):

From: Rene Engelhard <rene@debian.org>
To: Salvatore Bonaccorso <carnil@debian.org>, 876001@bugs.debian.org
Cc: team@security.debian.org
Subject: Re: Bug#876001: libwpd: CVE-2017-14226
Date: Sun, 17 Sep 2017 13:59:20 +0200
[Message part 1 (text/plain, inline)]
Hi,


On Sun, Sep 17, 2017 at 10:47:06AM +0200, Salvatore Bonaccorso wrote:
> Source: libwpd
> Version: 0.10.1-5
> Severity: important
> Tags: patch security upstream
> Forwarded: https://sourceforge.net/p/libwpd/tickets/14/
> 
> Hi,
> 
> the following vulnerability was published for libwpd.
>
> CVE-2017-14226[0]:
[...]

fixed in 0.10.2-1 for sid. Want this fixed as DSAs for jessie/stretch?

Prepared packages. Debdiffs attached...

Regards,

Rene
[CVE-2017-14226-stretch.debdiff (text/plain, attachment)]
[CVE-2017-14226-jessie.debdiff (text/plain, attachment)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>:
Bug#876001; Package src:libwpd. (Sun, 17 Sep 2017 12:57:03 GMT) (full text, mbox, link).


Acknowledgement sent to Rene Engelhard <rene@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>. (Sun, 17 Sep 2017 12:57:03 GMT) (full text, mbox, link).


Message #32 received at 876001@bugs.debian.org (full text, mbox, reply):

From: Rene Engelhard <rene@debian.org>
To: Salvatore Bonaccorso <carnil@debian.org>, 876001@bugs.debian.org
Cc: team@security.debian.org
Subject: Re: Bug#876001: libwpd: CVE-2017-14226
Date: Sun, 17 Sep 2017 14:54:12 +0200
Hi again,

On Sun, Sep 17, 2017 at 01:59:20PM +0200, Rene Engelhard wrote:
> On Sun, Sep 17, 2017 at 10:47:06AM +0200, Salvatore Bonaccorso wrote:
> > Source: libwpd
> > Version: 0.10.1-5
> > Severity: important
> > Tags: patch security upstream
> > Forwarded: https://sourceforge.net/p/libwpd/tickets/14/
> > 
> > Hi,
> > 
> > the following vulnerability was published for libwpd.
> >
> > CVE-2017-14226[0]:
> [...]
> 
> fixed in 0.10.2-1 for sid. Want this fixed as DSAs for jessie/stretch?

Ah, nevermind. I should have looked at the security tracker :):

[stretch] - libwpd <no-dsa> (Minor issue)
[jessie] - libwpd <no-dsa> (Minor issue)

OK.

It's in git now, for a possible later fix we can include this, too.

Regards,
 
Rene



Information forwarded to debian-bugs-dist@lists.debian.org, Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>:
Bug#876001; Package src:libwpd. (Sun, 17 Sep 2017 13:12:07 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>. (Sun, 17 Sep 2017 13:12:07 GMT) (full text, mbox, link).


Message #37 received at 876001@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Rene Engelhard <rene@debian.org>, 876001@bugs.debian.org
Cc: team@security.debian.org
Subject: Re: Bug#876001: libwpd: CVE-2017-14226
Date: Sun, 17 Sep 2017 15:08:19 +0200
Hi Rene!

On Sun, Sep 17, 2017 at 02:54:12PM +0200, Rene Engelhard wrote:
> Hi again,
> 
> On Sun, Sep 17, 2017 at 01:59:20PM +0200, Rene Engelhard wrote:
> > On Sun, Sep 17, 2017 at 10:47:06AM +0200, Salvatore Bonaccorso wrote:
> > > Source: libwpd
> > > Version: 0.10.1-5
> > > Severity: important
> > > Tags: patch security upstream
> > > Forwarded: https://sourceforge.net/p/libwpd/tickets/14/
> > > 
> > > Hi,
> > > 
> > > the following vulnerability was published for libwpd.
> > >
> > > CVE-2017-14226[0]:
> > [...]
> > 
> > fixed in 0.10.2-1 for sid. Want this fixed as DSAs for jessie/stretch?
> 
> Ah, nevermind. I should have looked at the security tracker :):
> 
> [stretch] - libwpd <no-dsa> (Minor issue)
> [jessie] - libwpd <no-dsa> (Minor issue)
> 
> OK.

Thanks for the quick updates, impressing :)

> It's in git now, for a possible later fix we can include this, too.

Sicne the point releases are approaching, can you shedule the fixes
since already prepared in the next point release?

Regards and thanks again for your work,
Salvatore



Information forwarded to debian-bugs-dist@lists.debian.org, Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>:
Bug#876001; Package src:libwpd. (Sun, 17 Sep 2017 13:21:12 GMT) (full text, mbox, link).


Acknowledgement sent to Rene Engelhard <rene@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>. (Sun, 17 Sep 2017 13:21:12 GMT) (full text, mbox, link).


Message #42 received at 876001@bugs.debian.org (full text, mbox, reply):

From: Rene Engelhard <rene@debian.org>
To: Salvatore Bonaccorso <carnil@debian.org>, 876001@bugs.debian.org
Cc: team@security.debian.org
Subject: Re: Bug#876001: libwpd: CVE-2017-14226
Date: Sun, 17 Sep 2017 15:20:10 +0200
On Sun, Sep 17, 2017 at 03:08:19PM +0200, Salvatore Bonaccorso wrote:
> Sicne the point releases are approaching, can you shedule the fixes
> since already prepared in the next point release?

*sigh* :). Just that I need to build that again without -sa..

Bugs filed.

Regards,

Rene



Reply sent to Rene Engelhard <rene@debian.org>:
You have taken responsibility. (Sun, 24 Sep 2017 13:51:06 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Sun, 24 Sep 2017 13:51:06 GMT) (full text, mbox, link).


Message #47 received at 876001-close@bugs.debian.org (full text, mbox, reply):

From: Rene Engelhard <rene@debian.org>
To: 876001-close@bugs.debian.org
Subject: Bug#876001: fixed in libwpd 0.10.1-5+deb9u1
Date: Sun, 24 Sep 2017 13:47:51 +0000
Source: libwpd
Source-Version: 0.10.1-5+deb9u1

We believe that the bug you reported is fixed in the latest version of
libwpd, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 876001@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Rene Engelhard <rene@debian.org> (supplier of updated libwpd package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sun, 17 Sep 2017 13:20:30 +0200
Source: libwpd
Binary: libwpd-dev libwpd-0.10-10 libwpd-tools libwpd-doc
Architecture: source
Version: 0.10.1-5+deb9u1
Distribution: stretch
Urgency: medium
Maintainer: Debian LibreOffice Maintainers <debian-openoffice@lists.debian.org>
Changed-By: Rene Engelhard <rene@debian.org>
Description:
 libwpd-0.10-10 - Library for handling WordPerfect documents (shared library)
 libwpd-dev - Library for handling WordPerfect documents (development)
 libwpd-doc - Library for handling WordPerfect documents (documentation)
 libwpd-tools - Tools from libwpd for converting WordPerfect to HTML/RAW/Text
Closes: 876001
Changes:
 libwpd (0.10.1-5+deb9u1) stretch; urgency=medium
 .
   * debian/patches/libwpd-tdf112269.diff: backport patch to fix
     CVE-2017-14226 (closes: #876001)
Checksums-Sha1:
 0b8612a54dc11a187297d46e6678efdf822b18f6 2066 libwpd_0.10.1-5+deb9u1.dsc
 143f68e58012741e71e1b8f4f7ca7915c7373a69 11836 libwpd_0.10.1-5+deb9u1.debian.tar.xz
 57eb63e966472c09f79641e29f2406038939e18e 5384 libwpd_0.10.1-5+deb9u1_source.buildinfo
Checksums-Sha256:
 daa211e797c063f76e2d7692335a81ecddbfd0ef786eddd4e54e112d3ba011d2 2066 libwpd_0.10.1-5+deb9u1.dsc
 3045c8762a0ec2b9855cd86d083d9144283fbeb13f77fd24cff4cdaa9656e2af 11836 libwpd_0.10.1-5+deb9u1.debian.tar.xz
 57f8aced23e69337b933c886994332f3707b502713a2a0d32d101eefe04fd5c0 5384 libwpd_0.10.1-5+deb9u1_source.buildinfo
Files:
 c2fa32d90b37144f5d1a0ece0bb02e29 2066 devel optional libwpd_0.10.1-5+deb9u1.dsc
 a619839cb266f6ebb1cdc6e7a96bfe1c 11836 devel optional libwpd_0.10.1-5+deb9u1.debian.tar.xz
 cdbd09e7e7dee291d711df2783d529dc 5384 devel optional libwpd_0.10.1-5+deb9u1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE4S3qRnUGcM+pYIAdCqBFcdA+PnAFAlnGl1AACgkQCqBFcdA+
PnAL3Q/+LgM2Tua6X9wD6jjTXXjmCfsKsA4207zfLY9T8WbwuYR2CL0x5aipe0th
oH6sW1SZbOhT89Rm8cMQY+Ofa7vgBd9fEecgZzW2Do7lj7FiU7lLCMzABpwR+SpH
uwIdH1MVjiPKTgdT0Vd5cHIPOirsWoP2D3JZQCmCnC8Vo95oBXTT8DpVJJb3xShG
DsFy/JLDeWi/OvpmcJFefqjCiIHsJZJZFB/ZMkAHZerfwgtpc7teA2QR8Zkyg/4b
D7SuF0fcVN0cM1UaJcKuRxTNI+ZE0j+qcChiWtNP3yKAhKtFe/mB/FOsGQFB+gtH
2+9fb/HLuMegPhBxIdr8ewVaG8IYXc7Q/kNdDbYodxfDUZRZurHAwO0I965dynMA
1h97Wyajp0zDQr2POUkvFsh5CAypxG8JlSVqG+JY2/cBTnjDE331JoY0nFqwSBoY
de5haEeJ76Q/p7c4jnYaK+Oo1JlYCcpFkHQFGvKd2vh4SsKRCWAldNPd1M60rNmh
3KbukKWZCOil16sFnU5koNwhJCRCAqvyNBYwVRzjYh/9uIHL5vtEgmF/b9160mam
WNm7dc2vU12uilxyF76zIfuKDe2lViyPkCx8hxcmVVV7SRWenA2JErpz0x3vM8E1
sP/fQC4jk8boGbnUY9rGU1m+oOle7X7rcSqz+NHDoI6W9+q38Co=
=uLbP
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 23 Oct 2017 07:24:50 GMT) (full text, mbox, link).


Bug unarchived. Request was from rene@rene-engelhard.de (Rene Engelhard) to control@bugs.debian.org. (Sat, 18 Nov 2017 21:54:06 GMT) (full text, mbox, link).


Bug archived. Request was from rene@rene-engelhard.de (Rene Engelhard) to control@bugs.debian.org. (Sat, 18 Nov 2017 21:54:08 GMT) (full text, mbox, link).


Bug unarchived. Request was from rene@rene-engelhard.de (Rene Engelhard) to control@bugs.debian.org. (Sat, 18 Nov 2017 22:39:08 GMT) (full text, mbox, link).


Marked as fixed in versions libwpd/0.10.0-2+deb8u1. Request was from rene@rene-engelhard.de (Rene Engelhard) to control@bugs.debian.org. (Sat, 18 Nov 2017 22:39:08 GMT) (full text, mbox, link).


Bug archived. Request was from rene@rene-engelhard.de (Rene Engelhard) to control@bugs.debian.org. (Sat, 18 Nov 2017 22:39:09 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 15:01:25 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.