oss-sec mailing list archives
Re: Re: [Officesecurity] CVE Request (minor) -- LibreOffice (X >= v3.5.0): DoS (excessive CPU use) in the RTF tokenizer
From: Moritz Muehlenhoff <jmm () debian org>
Date: Thu, 19 Apr 2012 18:41:22 +0200
On Thu, Apr 19, 2012 at 01:33:07PM +0100, Caolán McNamara wrote:
[8] https://bugs.freedesktop.org/show_bug.cgi?id=48640#c1 ('DoS PoC') This one (on LibreOffice >= v.3.5.0 using the new RTF tokenizer implementation) truly leads to denial of service (excessive CPU consumption and hang) while trying to process that RTF file. So this case might be applicable for CVE-2012-* identifier assignment.Dunno about this, I mean if we're going to go around assigning CVEs to every busy-hang we'd be knee deep in CVEs by the end of a week.
I agree. For an application profile such as an office suite handing out CVE IDs to crash/CPU overload bug w/o potential of code injection is a waste of time and impractical. Cheers, Moritz
Current thread:
- CVE Request (minor) -- LibreOffice (X >= v3.5.0): DoS (excessive CPU use) in the RTF tokenizer Jan Lieskovsky (Apr 19)
- Re: [Officesecurity] CVE Request (minor) -- LibreOffice (X >= v3.5.0): DoS (excessive CPU use) in the RTF tokenizer Caolán McNamara (Apr 19)
- Re: [Officesecurity] CVE Request (minor) -- LibreOffice (X >= v3.5.0): DoS (excessive CPU use) in the RTF tokenizer Miklos Vajna (Apr 19)
- Re: Re: [Officesecurity] CVE Request (minor) -- LibreOffice (X >= v3.5.0): DoS (excessive CPU use) in the RTF tokenizer Moritz Muehlenhoff (Apr 19)
- Re: [Officesecurity] CVE Request (minor) -- LibreOffice (X >= v3.5.0): DoS (excessive CPU use) in the RTF tokenizer Caolán McNamara (Apr 19)