[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20150425115046.GA30722@pisco.westfalen.local>
Date: Sat, 25 Apr 2015 13:50:47 +0200
From: Moritz Muehlenhoff <jmm@...ian.org>
To: bugtraq@...urityfocus.com
Subject: [SECURITY] [DSA 3236-1] libreoffice security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-3236-1 security@...ian.org
http://www.debian.org/security/ Moritz Muehlenhoff
April 25, 2015 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : libreoffice
CVE ID : CVE-2015-1774
It was discovered that missing input sanitising in Libreoffice's filter
for HWP documents may result in the execution of arbitrary code if a
malformed document is opened.
For the oldstable distribution (wheezy), this problem has been fixed in
version 1:3.5.4+dfsg2-0+deb7u4.
For the stable distribution (jessie), this problem has been fixed in
version 1:4.3.3-2+deb8u1.
For the unstable distribution (sid), this problem will be fixed soon.
We recommend that you upgrade your libreoffice packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@...ts.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBAgAGBQJVO39VAAoJEBDCk7bDfE42gacP+wWENf5x88cO1SPpA3Jgpfav
6FylLJBl046ZI9pKUDwVOQvzSr5XdVNXg5oDmCyY29Ej3qOlSNd5RcYmB3EQdYS3
swCwndpyTnNdKCOjpEbbT7YB8wl9fhe4+/Iassj6tFnQGvXxa5ItJAqWJPpyaXSM
N+u6eZqItBhDdFmKcUL9TG0KSLYKJ7ND0odj7kr2P5Sf00ublsoMfNKCzekjba61
4bl9/7ieOZttU2SVRr8hNjtgJckQRW06hm1PuvxipuSOYGH16BhbQ8GwAnBP6gK0
Fgd9TpRbUsQyx/fKnhy/5kdRgDNpyF2wEfVMSffBXH7bpxk6z958RJwBJ7PEgqQ/
LNYJa1tgHHG6GAhKe9mpZttcSPwddzh1x65DIekLmVSWiJMEKMnHmKQzNgxLGSyM
fYch0hYTgq84+87IG9Me7IAJT7LHg9ZWeN8mZE9eqrybGX0Jp0eZaunKAqOzJv/Z
YsX2/+AKWYKudMss78po/lpaCt/xLHR+4X8WSy40My+LClv5gt3WsrbH21rcw8ov
5o0orcB5l1XWDawwTLlg4QQBWI5+qUqJCM+WbvxEL2Ao70FKBMOM9Jq+3Rj3l4ep
ano3nW357JW+SZe42A+COBdO68G0PzC8LSUq774ALQ/FMoClFWjRuk/OzRpYcxL7
pVaD4TXvlbVUtjGu/h+S
=6eYI
-----END PGP SIGNATURE-----
Powered by blists - more mailing lists