Summary: | app-office/{libreoffice,openoffice} {,-bin}: automatic opening of embedded external data (CVE-2012-5639) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED UPSTREAM | ||
Severity: | minor | CC: | chithanh |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=887416 | ||
See Also: |
https://issues.apache.org/ooo/show_bug.cgi?id=121493 https://bugs.gentoo.org/show_bug.cgi?id=447378 |
||
Whiteboard: | B4 [noglsa] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | |||
Bug Blocks: | 447378, 447384 |
Description
Agostino Sarubbo
2012-12-15 18:27:49 UTC
LibreOffice states this is fixed in 4.2 by introducing a stealth mode: http://whatofhow.wordpress.com/2013/12/02/stealth-mode/ (from https://bugs.freedesktop.org/show_bug.cgi?id=58295#c2 ). If that can be verified it is already stabilized. (In reply to Kristian Fiskerstrand from comment #1) > LibreOffice states this is fixed in 4.2 by introducing a stealth mode: > http://whatofhow.wordpress.com/2013/12/02/stealth-mode/ (from > https://bugs.freedesktop.org/show_bug.cgi?id=58295#c2 ). If that can be > verified it is already stabilized. The option is there in app-office/libreoffice-bin-5.0.3.2. Upstream has closed this as invalid due to lack of information. Warn the user via ewarn or release a GLSA, thoughts? *** Bug 447378 has been marked as a duplicate of this bug. *** Per my previous comments and that of dilfridge from bug 447378 upstream has designed functionality to provide a "stealth mode" in the newest tree stable versions of libreoffice. Upstream has closed this as WONTFIX. No reply from maintainers regarding a warning for users. |