LWN.net Logo

Debian alert DSA-2520-1 (openoffice.org)

From:  Yves-Alexis Perez <corsac@debian.org>
To:  debian-security-announce@lists.debian.org
Subject:  [SECURITY] [DSA 2520-1] openoffice.org security update
Date:  Thu, 2 Aug 2012 21:31:04 +0200 (CEST)
Message-ID:  <20120802193109.0504835EF@scapa.corsac.net>
Archive-link:  Article, Thread

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2520-1 security@debian.org http://www.debian.org/security/ Yves-Alexis Perez August 01, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openoffice.org Vulnerability : Multiple heap-based buffer overflows Problem type : local Debian-specific: no CVE ID : CVE-2012-2665 Debian Bug : Timo Warns from PRE-CERT discovered multiple heap-based buffer overflows in OpenOffice.org, an office productivity suite. The issues lies in the XML manifest encryption tag parsing code. Using specially crafted files, an attacker can cause application crash and could cause arbitrary code execution. For the stable distribution (squeeze), this problem has been fixed in version 3.2.1-11+squeeze7. openoffice.org package has been replaced by libreoffice in testing (wheezy) and unstable (sid) distributions. For the testing distribution (wheezy), this problem has been fixed in version 1:3.5.4-7. For the unstable distribution (sid), this problem has been fixed in version 1:3.5.4-7. We recommend that you upgrade your openoffice.org packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCgAGBQJQGtV4AAoJEDBVD3hx7wuokBsP/3t05CwoFnMJJMNq6XhkvyPP dSRYYdNQA5XH6Pd1YQH7h6XVZKjeQafY1SIpr1zrbFTl3rJkuDR817HhLdkoZZHC 8JbHvp9mzUbT8Y6Hhbq/Cc+5BaPtfiOHhymF1BJQAlO+O2KlD4MuZsVGlFmUuV7v KJtTyJT7tHx3ntmqylamH1+9nDzKXGplsRddZFFWmS9N0cZoji3Nh45G6nN94sdr OUqsNUC2lFqEgldUjyeRc5QL2uINM3+NPcU9zpdMNBYDm5DZBxDOeEU/asdBfgPs mjX4vbXsPiaxPL78pvfIhz/fTE68pkCebdNZC41d+mkqpdJIq0vGvYHlZ2Lz0E+T BhwBRw1oesz08DA6+dy/beIeIL8ASAvVE/eQdzfCVMLMqLkQKClj+XybKv2/LT+l UN70miF9eeosAAB70208G+N4DR3QYv3s3h7ZBHfJJC/1UUBllfoiJHpb+QpZhnyI HwwrdDvMT/PmmN+3IL9aa6hWKyJuV7lX+Rq/jRzEZB+w7EcR145vSCM68lpdjZ3X cVQaT/iw243j4koBm865SzCRKfKayWfvAa8vj2PI/I79MHNcfuu+d6brDVDW6m02 gQAwjT8UVyfwtNwovVtxi4csjBsX/cByFHQs6nyFdmjlbaN0xq0As40MgzZAdSXl IKI70drvK8OCEexPfzf9 =ymEK -----END PGP SIGNATURE----- -- To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org Archive: http://lists.debian.org/20120802193109.0504835EF@scapa.co...


(Log in to post comments)

Debian security update to openoffice.org

Posted Aug 3, 2012 18:19 UTC (Fri) by micka (subscriber, #38720) [Link]

Openoffice ?
I was very surprised to see that name. For a veeeery long time, it's been named libreoffice in debian. Openoffice is just a transitional package that depends on libreoffice.

Did they introduce a vulnerability in a transitional package ?

Debian security update to openoffice.org

Posted Aug 3, 2012 18:46 UTC (Fri) by jimparis (subscriber, #38647) [Link]

>I was very surprised to see that name. For a veeeery long time, it's been named libreoffice in debian. Openoffice is just a transitional package that depends on libreoffice.

It is still openoffice in the most recently released stable version of Debian, which is still "squeeze". You're thinking of the unreleased testing distro, "wheezy"

As the advisory says:

> openoffice.org package has been replaced by libreoffice in testing (wheezy) and unstable (sid) distributions.

The versions they list for wheezy and sid are version numbers for the libreoffice packages.

Debian security update to openoffice.org

Posted Aug 3, 2012 19:08 UTC (Fri) by micka (subscriber, #38720) [Link]

Ah I read too fast, thanks.

Actually, I wasn't even thinking of wheezy but of sid (even if at the moment, they're not really different).

I had forgotten that there was something even older than Wheezy that still had security updates. Not that stable has no use : I have a NAS with Squeeze (because the trouble caused by a broken upgrade is greater when you don't even have console access), but of course I wouldn't install *office on it.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds