Candidate: CVE-2013-4156 PublicDate: 2013-07-31 13:20:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4156 Description: Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted element in an OOXML document file. Ubuntu-Description: Notes: jdstrand> application termination mdeslaur> precise is fixed in Correct-the-XML-document-handler.diff Bugs: https://bugs.launchpad.net/ubuntu/+source/libreoffice/+bug/1316243 Priority: low Discovered-by: Assigned-to: CVSS: Patches_openoffice.org: upstream_openoffice.org: needs-triage lucid_openoffice.org: ignored (reached end-of-life) precise_openoffice.org: not-affected (transitional packages) quantal_openoffice.org: DNE raring_openoffice.org: DNE saucy_openoffice.org: DNE trusty_openoffice.org: DNE trusty/esm_openoffice.org: DNE utopic_openoffice.org: DNE devel_openoffice.org: DNE Patches_libreoffice: upstream: http://cgit.freedesktop.org/libreoffice/core/commit/writerfilter/source/ooxml/OOXMLDocumentImpl.cxx?id=d94bda0c1fd3c618b98a63f76d71e129ad06d942 upstream_libreoffice: released (4.0.4) lucid_libreoffice: DNE precise_libreoffice: released (1:3.5.7-0ubuntu6) quantal_libreoffice: ignored (reached end-of-life) raring_libreoffice: ignored (reached end-of-life) saucy_libreoffice: not-affected (1:4.1.2~rc3-0ubuntu1) trusty_libreoffice: not-affected (1:4.2.3~rc3-0ubuntu2) trusty/esm_libreoffice: DNE (trusty was not-affected [1:4.2.3~rc3-0ubuntu2]) utopic_libreoffice: not-affected (1:4.2.3~rc3-0ubuntu2) devel_libreoffice: not-affected (1:4.2.3~rc3-0ubuntu2)