Summary: | <app-office/libreoffice-4.2.6.3: two vulnerabilities (CVE-2014-{3524,3575}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | asturm |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://blog.documentfoundation.org/2014/08/28/libreoffice-4-3-1-fresh-announced/ | ||
Whiteboard: | B3 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
![]() CVE-2014-3575 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3575): The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to embed arbitrary data into documents via crafted OLE objects. *** Bug 521852 has been marked as a duplicate of this bug. *** I've just added 4.2.6.3 to the tree where this is fixed. Let's wait a few days and then stabilize it (including bin packages that still need to be built). Will call for stabilize on or after Sept 16. (In reply to Yury German from comment #4) > Will call for stabilize on or after Sept 16. Sounds good. Here's the list of packages to test and stabilize (all amd64 x86): app-office/libreoffice-4.2.6.3 app-office/libreoffice-bin-4.2.6.3 app-office/libreoffice-bin-debug-4.2.6.3 app-office/libreoffice-l10n-4.2.6.3-r1 Arches, please test and mark stable: =app-office/libreoffice-4.2.6.3 =app-office/libreoffice-bin-4.2.6.3 =app-office/libreoffice-bin-debug-4.2.6.3 =app-office/libreoffice-l10n-4.2.6.3-r1 Target Keywords : "amd64 x86" Thank you! amd64 stable x86 stable. Maintainer(s), please cleanup. Security, please vote. All vulnerable versions removed. Arches and Maintainer(s), Thank you for your work. GLSA Vote: Yes Added to existing GLSA (eafa83859) This issue was resolved and addressed in GLSA 201603-05 at https://security.gentoo.org/glsa/201603-05 by GLSA coordinator Kristian Fiskerstrand (K_F). |