From ${URL} : Common Vulnerabilities and Exposures assigned an identifier CVE-2013-6836 to the following vulnerability: Name: CVE-2013-6836 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6836 Assigned: 20131120 Reference: https://bugzilla.gnome.org/show_bug.cgi?id=712772 Reference: https://git.gnome.org/browse/gnumeric/commit/?id=b5480b69345b3c6d56ee0ed9c9e9880bb2a08cdc Reference: https://projects.gnome.org/gnumeric/announcements/1.12/gnumeric-1.12.9.shtml Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value. @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
CVE-2013-6836 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6836): Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.
+*goffice-0.10.9 (05 Jan 2014) + + 05 Jan 2014; Pacho Ramos <pacho@gentoo.org> +goffice-0.10.9.ebuild: + Version bump + +*gnumeric-1.12.9 (05 Jan 2014) + + 05 Jan 2014; Pacho Ramos <pacho@gentoo.org> +gnumeric-1.12.9.ebuild, + -gnumeric-1.12.7.ebuild: + Version bump, drop old + Feel free to CC arches when you need it
the fixed versions were stabilized time ago
stabilized in bug 499954
also affected ebuilds were removed
GLSA Vote: No