SuSE alert SUSE-SA:2007:037 (OpenOffice_org)
From: | Marcus Meissner <meissner@suse.de> | |
To: | opensuse-security-announce@opensuse.org | |
Subject: | [security-announce] SUSE Security Announcement: OpenOffice_org (SUSE-SA:2007:037) | |
Date: | Thu, 28 Jun 2007 16:37:56 +0200 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Announcement Package: OpenOffice_org Announcement ID: SUSE-SA:2007:037 Date: Thu, 28 Jun 2007 14:00:00 +0000 Affected Products: SUSE LINUX 10.0 SUSE LINUX 10.1 openSUSE 10.2 SuSE Linux Desktop 1.0 Novell Linux Desktop 9 SUSE Linux Enterprise Desktop 10 SP1 SLE SDK 10 SP1 Vulnerability Type: remote code execution Severity (1-10): 7 SUSE Default Package: yes Cross-References: CVE-2007-0245 Content of This Advisory: 1) Security Vulnerability Resolved: OpenOffice_org RTF importer buffer overflow Problem Description 2) Solution or Work-Around 3) Special Instructions and Notes 4) Package Location and Checksums 5) Pending Vulnerabilities, Solutions, and Work-Arounds: See SUSE Security Summary Report. 6) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Problem Description and Brief Discussion The Office suite OpenOffice_org was updated to fix a heap buffer overflow in its RTF parser. This issue could be used by attackers sending specially crafted RTF files to potentially execute code and it is tracked by the Mitre CVE ID CVE-2007-0245. Packages for SUSE Linux 10.0, SUSE Linux 10.1 and openSUSE 10.2 on June 20th, for SUSE Linux Desktop 1.0 and Novell Linux Desktop on June 15th, for SUSE Linux Enterprise Desktop 10 on June 28th. For SUSE Linux Enterprise 10 additional non-security bugs were fixed. 2) Solution or Work-Around There is no known workaround, please install the update packages. 3) Special Instructions and Notes Restart OpenOffice_org after the update. 4) Package Location and Checksums The preferred method for installing security updates is to use the YaST Online Update (YOU) tool. YOU detects which updates are required and automatically performs the necessary steps to verify and install them. Alternatively, download the update packages for your distribution manually and verify their integrity by the methods listed in Section 6 of this announcement. Then install the packages using the command rpm -Fhv <file.rpm> to apply the update, replacing <file.rpm> with the filename of the downloaded RPM package. x86 Platform: openSUSE 10.2: ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 51898edcd0066bf5db3cedad07f8eb7d ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 5a386f4613e9fa593bbb0febc8b2ebd7 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 159e81d0f12c8212c1f8b76766068422 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 073ed944485e24021c26915e5fbc2be7 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 5e7b3c404d5f0c69da3410ae951ddcb5 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 379600c59f14ecbfb2b14c5a51476fb9 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... ad787bd9ba581a806e9bbe1260e85475 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 1db9cf326f5e122ec2d6a756cf7ef87f ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... dfb32bfae04a29cc1c24b50cd45e757c ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 4e6feb4d16b76b213ae4a1a34be00ed4 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... f5c258380a1464ebce7ed992075221ff ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... a4d70546cde7c6306046cec175b1d66f ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 961df04e1e1721e486451b28e9eec3c5 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 3adb1a3e7ab4e1f4efb925e4c292050e ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... de92cc231d938949f445f80ec0fd25eb ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 572e2c710da34054791ddb5298fc92e7 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 331315cddd0cee2d849fcdd738003447 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 2ab9941f27ed9564bdc460730790fba5 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... c32139444331a9806864d236e3e30f58 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... f119b58edeaf4335d556ce9b4d0d337d ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 824ab567729a2b21548fb650d8485dcb ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 1e0d03cd7fd7f70d4a749840f79058e5 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 70676f1211e94bf774c2cc2e7ac3dd0c ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 2c6b930dc1c579c464e54e0c6e4e0b9b ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 471f57da7a11c64d8d40a8945f55764f ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... c75c2c0e32ba1a783d8fb574d4eb9219 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... bb2e438581999acf030add33ca0d2bd0 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... f06d5113f7f03c59a007c3d4ce850aae ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... e763bbb3c7ac189bc9775dea3bace346 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 55095b147ae4edc0c6f628d8f799f9c5 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... bf1236eb5171cda29b5f8c1ccd427d27 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/i586/OpenOffi... 39d40f3439ac2a1a34f43304365346cd SUSE LINUX 10.1: ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 5f57c296c190435760425417fc51af48 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 1d1b49353aaab53fdc563e415722bded ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... e655c17261382e9d3bfe21c717fee0f9 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 8a915b0d398878820ddea5563a822080 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... b4c964321e33e545e1708065b720ea69 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 88db08e9b9119905d514cff7726a68fd ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 89fe97cede7f2a6cbe509dd4443f819f ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 8db09131f31982271850f166993e51a3 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... af39def1adcd3148053dcf95df9376a3 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 5b318d65acd3d4de36fbe3d30038555d ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... df73c796adb6d0f86ca213462379a7d5 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 0e017f063af917aa540a01c301cab924 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 62ec71c8589aa5f81955140651abf02b ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... b0bab2be2088c9c6ba4c60bbb2b9076b ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 0b3e1bfbb0f6b19854ac4f09fdcbd309 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 4b977d7bb609dd9e8803ce1226c27afb ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 78b6555824f6e44ebbbeba461071b347 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 3cd270b7905964f1182e77ddca7c1868 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 16bb6508f14cc44902089c19df90e6ea ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 367fe07b826e76196860afa88672d00b ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 7e5fd94a8d2a32dd7ab915ae320a2176 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 096fcbdb99de03d1d9dd4ee12bd5ea54 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 0cc8bb6370c7e741159ed385a0f02119 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 90168189c194fad4f504551cc8ffc81b ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... c1a527c22aa1d8ca4b09762862a8db12 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... f29a4aeeeaba68fd580e97232e92ae34 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 9fd399cd1ceabc83e3d24d95d88c103c ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 6d1224bc5bd41f04ba4a832fd08e057a ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 83273e94c3d7b8fcbe239f829f6b2a11 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 7fb1daef50ce7bffb8ea4960fff5e7f4 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... 56993d330f3007bacc44375019997208 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... c2e34c7d84ee85875eafb2922e7a8211 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/i586/OpenOffi... dbf2a2480ef81c6fff996b49036405c0 SUSE LINUX 10.0: ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... d7c31b14a0772a4263007d22094aae6a ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... eac86287f4e859555b70dd5470d88e1d ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 48429fd4082e246325dc94887ffb9d07 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... d35651c52aa3702a88c960807582c938 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... dcf0fba4826ac78c8dbec12cba143c96 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 7425a54da5615adef46634d4955ba5ba ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... c92eaa2ec45c46cd17d4c4ec194b604a ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 46c8e37f6a8d73d248c5573c3b8262a6 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 4fb592edf077d7d55d0597595a96a4c2 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 1414ddc1d9093976992dfdae6e534e70 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 3fbdcd8266bb32ef7f59bb4c63ab3942 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 4225fd3a50f8333cdfbe9f09a61c99c2 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 1ea78aa3755c66ab6d834281b3fe16c1 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... c6b6ce2cde7eafcc61f84b18d0b8eb9b ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 6fe8c5aef1dabf941d20cfad0a4bb1c8 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 2eb1521a0fde5648d2ec8c862a2bbff2 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... fba17ad4b94778ff51543f2919cee9aa ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 5c2075edca251fcbd567b955835db8b0 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 07a16f4f4d46dd44ae073a947f57766a ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... ab9459ca19815e16597db265b954e273 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 94ee43a96cdac0b7d8189052005902f9 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 2b21657a9c12c9f007bd8ea009620394 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 1a90d306e3df987893682564576af13f ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... a8181b279aa5ecc5680a8c4ce9fd44ec ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 71322e2e55d2da981ba8f549b7234f95 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 15052978f611da0e8c846a13cfce67af ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... fdcdc88f4462132069040fa0584a4549 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... d2317e08f52efbfeee7d312854e28d07 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... e75d4d90df758d15cdc6e680608e386c ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 7156a686c14e0e731e77f6a2bbf3e68a ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 138dcebc9cc1df50b1116303d477d196 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 9c139fb169f20e59fe5bd226b5785ded ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/Ope... 782764adb7e2508489191c4287308c28 Power PC Platform: openSUSE 10.2: ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... 37be29a47a82076dc448647975fbaaa6 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... 9f5a09e18846a0de4cc2256063681b26 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... 1a1e1bbc36cf0cde8300df347fa15b60 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... aa93a943877f41b4e90ff51bf2f05f38 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... cb58ca884e85bf792cb919ffbe94ab2c ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... 6c88c5d32d66fc5b25cdce4663139138 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... 005bae67ac601f1b59354b05fd0ed39e ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... eedca9dedabcbc938d30924d0c117ee9 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... ccac046d11e327f6484deb4333b69714 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... f008b9b33ac419b14dfb06e9beb231a0 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... 00ed0dcdb31771252a92db4143c5e065 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... baa28af4096be173063a653664037c0e ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... e7c14a5df4875a07f8b125ad4e8ef95a ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... 353a11ed24d8e134dc4b0aaddaae43cc ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... e95bfa18d29f8ef95353310d8ac38cf6 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... a8dc0910be2f6d712f701fbbedd53da0 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... 5461da880a57e842e241ec96fc594a32 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... 6591c9f91f384fadb48a6ffb76c91543 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... a079f8e6a506cb47b69499ed50e6d7d7 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... c7a18ba75465d19d00a3365dcdbb7c91 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... 7238f01aac7112fb4cb4649edc926e1e ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... d2a0edf415c04e8598bd0ea7e7b19de8 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... c4cf8edb77c5efef20bceccbcca6507d ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... 51b1e666ae6e049c47fe9f3c8f1aa148 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... 628b7dcb6122db6edeeb7600079bbd25 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... e1cd5a85a3457b1bf1517b21b3572d10 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... 0d6d2ed948636cb31ad86627c3b641da ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... cf383fb07ce44bd47db66f469dae8fc8 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... c75a23d1257a0427ef736a15c4199d25 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... 9e7c66d5c151ebc7946e4b651df32f93 ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... 69f0a907a8ac0abd7a0d5127387d163a ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/OpenOffic... c9256b708bbd23b26e7b7a28b082d312 SUSE LINUX 10.1: ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... eb6e3ccc47af70456f72fad106ffad09 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 6f76970b1728f3c9c662625706bf86bd ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 3b6a81ba7415b17f8e16f16d7a5a512d ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 3a29086442f28f3c8e13a4543efaf662 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... ead0172dc888d44be376070ef402e53e ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 274ef45683be24117a4abfcdb0d56a12 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 8a90918a8f75ff5de00a2c7b13f328cf ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... d027365008dc6134477c099c7145426b ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... fee926420559a793e517dc3ef9e7f9b7 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 5ef213b6ec357cba58430fe607802154 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... d821a98cc9fbf682f103b60eb247bf16 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... a89cefcdd9ea2e5c31620bd8255104eb ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 8c83c3b0238b874864955fc987be474b ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 91053fabb2b03bce8fcee323fbe42386 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... e704a64d1eff4008b493c8f7d44b89bf ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 1e761e8e1c907677a0a81b32870e7b53 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 21e34b6244b9e4bfead9d7619770d6d9 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 934984d83f9b8a0a8f9b2a1a90dae589 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 71dd0dbbb20df191317f21d56aa63c0c ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... b691eccab9c25a1bac7819ba2a58be77 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 5ed4070198506a82861b8e708d5bceda ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... b97c9536f0a91c7ddf5d0f8bf99fe59c ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 40d1a9db46a5c5b0171e2cc2e62ed58f ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 8e0e173102a5da12a6826d4cebc28fa0 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... a056df3542aca406e9f26d95a1817814 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 5ad6c26cc6013cbac9993674b83564a8 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... cfded44e33f0b1a267f2b4cf291c78ea ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 70cc334bab2f02f763f0947172159b10 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 3a464f80deaa474cb2b1bcd1a1e7d89f ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... f198fba8a33bfb6fd508bf7f31f46833 ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 34c7f5ff4ee8e6970e3bbaa217d55cbf ftp://ftp.suse.com/pub/suse/update/10.1/rpm/ppc/OpenOffic... 5bc0afbf6cd598b18b16a0627c86ca80 SUSE LINUX 10.0: ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... e3d0f25cba93eb8f00be159a21afe32f ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... c97e84fe4fde0ad309be0a2181f36112 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... a6aa012656e39f92ec1535fddccb44bd ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 840e74376bc5d48e3a094c8d3a8651d2 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... d4a4cf9b2fe60c2e8a25e2261c0c7c7a ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... e26c8ce4611318a0a35ed2c0e25afad4 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... da0ee7b9433a602d4deb05ac17dab1d1 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... aec4bdd8d179885b70a8e17e80ec7e5c ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... c8410ee0c6184e46368d69b6e72be530 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 043ac0569601bc0a46b6db595a354b6b ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 95a946ec1a53f01032e63d644023d285 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 3acc47fb9374cf13aa48455a8543e74b ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... b907cfe5f464b12b7e376b419dcb8cea ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 4f95b0a6b16d7d729f15c261fe70d69c ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 3ef8c3c6b76d7ecb2038d686898ce560 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 9f601df2c2af641e14db296042e4273c ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 33f96a1f23813334a364a574617b7db5 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... d1bfaf976c989045f196d2aa3013c62b ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 8d52e0022f6907314ee17fb6c4ad2645 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 98d2ed1d3dbe0793d1ca6abbbb98cb7f ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 4009d4f2b2eb1ef5ac286b49c2dadac9 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 5dc9c921ae41181b10372321f47225cf ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... bb37d6e97c4516e66b873e27df98cd95 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 4077641eaa4e76522eeaea3dae7bc7ae ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... de53bbc54d5f02adea2bc67509d38096 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 40ac647fb7053630e6a369ced8c8a09d ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... c70749cb38e3e5c75296d06823ef6d3e ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 1fc89a11a00e857ef21cabcfbea14eee ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 341e135ea68e735ab9ebd0be2ed543a5 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 4ae56fa8a58693307cc7394d47eaae8c ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... 738ab8ab519b2bac4639c4199a08f88a ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/Open... e68c694fd63b9e990c7342df9b337019 Sources: openSUSE 10.2: ftp://ftp.suse.com/pub/suse/update/10.2/rpm/src/OpenOffic... 56ea32ccffc078652052979c8ad603d9 SUSE LINUX 10.1: ftp://ftp.suse.com/pub/suse/update/10.1/rpm/src/OpenOffic... a354b1077f3cc6885d5bbd43839dd3ee ftp://ftp.suse.com/pub/suse/update/10.1/rpm/src/OpenOffic... c3cd051ec445f40cdf25569af37a2b86 SUSE LINUX 10.0: ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/src/Open... a919ad5158eae993cb05ee637442e141 ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/src/Open... e9ac63ea9d41641cbebbb8d31d90a3b5 Our maintenance customers are notified individually. The packages are offered for installation from the maintenance web: SLE SDK 10 SP1 http://support.novell.com/techcenter/psdb/d79c3af9a7a1e5c... SUSE Linux Enterprise Desktop 10 SP1 http://support.novell.com/techcenter/psdb/d79c3af9a7a1e5c... Novell Linux Desktop 9 http://support.novell.com/techcenter/psdb/572ad014bcb9bd7... SuSE Linux Desktop 1.0 http://support.novell.com/techcenter/psdb/572ad014bcb9bd7... ______________________________________________________________________________ 5) Pending Vulnerabilities, Solutions, and Work-Arounds: See SUSE Security Summary Report. ______________________________________________________________________________ 6) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify <file> replacing <file> with the name of the file where you saved the announcement. The output for a valid signature looks like: gpg: Signature made <DATE> using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team <security@suse.de>" where <DATE> is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and the integrity of a package needs to be verified to ensure that it has not been tampered with. There are two verification methods that can be used independently from each other to prove the authenticity of a downloaded file or RPM package: 1) Using the internal gpg signatures of the rpm package 2) MD5 checksums as provided in this announcement 1) The internal rpm package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig <file.rpm> to verify the signature of the package, replacing <file.rpm> with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from build@suse.de with the key ID 9C800ACA. This key is automatically imported into the RPM database (on RPMv4-based distributions) and the gpg key ring of 'root' during installation. You can also find it on the first installation CD and at the end of this announcement. 2) If you need an alternative means of verification, use the md5sum command to verify the authenticity of the packages. Execute the command md5sum <filename.rpm> after you downloaded the file from a SUSE FTP server or its mirrors. Then compare the resulting md5sum with the one that is listed in the SUSE security announcement. Because the announcement containing the checksums is cryptographically signed (by security@suse.de), the checksums show proof of the authenticity of the package if the signature of the announcement is valid. Note that the md5 sums published in the SUSE Security Announcements are valid for the respective packages only. Newer versions of these packages cannot be verified. - SUSE runs two security mailing lists to which any interested party may subscribe: opensuse-security@opensuse.org - General Linux and SUSE security discussion. All SUSE security announcements are sent to this list. To subscribe, send an e-mail to <opensuse-security+subscribe@opensuse.org>. suse-security-announce@suse.com - SUSE's announce-only mailing list. Only SUSE's security announcements are sent to this list. To subscribe, send an e-mail to <suse-security-announce-subscribe@suse.com>. ===================================================================== SUSE's security contact is <security@suse.com> or <security@suse.de>. The <security@suse.de> public key is listed below. ===================================================================== ______________________________________________________________________________ The information in this advisory may be distributed or reproduced, provided that the advisory is not modified in any way. In particular, the clear text signature should show proof of the authenticity of the text. SUSE Linux Products GmbH provides no warranties of any kind whatsoever with respect to the information contained in this security advisory. Type Bits/KeyID Date User ID pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security@suse.de> pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build@suse.de> - -----BEGIN PGP PUBLIC KEY BLOCK----- Version: GnuPG v1.4.2 (GNU/Linux) mQENAzbhLQQAAAEIAKAkXHe0lWRBXLpn38hMHy03F0I4Sszmoc8aaKJrhfhyMlOA BqvklPLE2f9UrI4Xc860gH79ZREwAgPt0pi6+SleNFLNcNFAuuHMLQOOsaMFatbz JR9i4m/lf6q929YROu5zB48rBAlcfTm+IBbijaEdnqpwGib45wE/Cfy6FAttBHQh 1Kp+r/jPbf1mYAvljUfHKuvbg8t2EIQz/5yGp+n5trn9pElfQO2cRBq8LFpf1l+U P7EKjFmlOq+Gs/fF98/dP3DfniSd78LQPq5vp8RL8nr/o2i7jkAQ33m4f1wOBWd+ cZovrKXYlXiR+Bf7m2hpZo+/sAzhd7LmAD0l09kABRG0JVN1U0UgU2VjdXJpdHkg VGVhbSA8c2VjdXJpdHlAc3VzZS5kZT6JARUDBRA24S1H5Fiyh7HKPEUBAVcOB/9b yHYji1/+4Xc2GhvXK0FSJN0MGgeXgW47yxDL7gmR4mNgjlIOUHZj0PEpVjWepOJ7 tQS3L9oP6cpj1Fj/XxuLbkp5VCQ61hpt54coQAvYrnT9rtWEGN+xmwejT1WmYmDJ xG+EGBXKr+XP69oIUl1E2JO3rXeklulgjqRKos4cdXKgyjWZ7CP9V9daRXDtje63 Om8gwSdU/nCvhdRIWp/Vwbf7Ia8iZr9OJ5YuQl0DBG4qmGDDrvImgPAFkYFzwlqo choXFQ9y0YVCV41DnR+GYhwl2qBd81T8aXhihEGPIgaw3g8gd8B5o6mPVgl+nJqI BkEYGBusiag2pS6qwznZiQEVAwUQNuEtBHey5gA9JdPZAQFtOAf+KVh939b0J94u v/kpg4xs1LthlhquhbHcKNoVTNspugiC3qMPyvSX4XcBr2PC0cVkS4Z9PY9iCfT+ x9WM96g39dAF+le2CCx7XISk9XXJ4ApEy5g4AuK7NYgAJd39PPbERgWnxjxir9g0 Ix30dS30bW39D+3NPU5Ho9TD/B7UDFvYT5AWHl3MGwo3a1RhTs6sfgL7yQ3U+mvq MkTExZb5mfN1FeaYKMopoI4VpzNVeGxQWIz67VjJHVyUlF20ekOz4kWVgsxkc8G2 saqZd6yv2EwqYTi8BDAduweP33KrQc4KDDommQNDOXxaKOeCoESIdM4p7Esdjq1o L0oixF12CohGBBARAgAGBQI7HmHDAAoJEJ5A4xAACqukTlQAoI4QzP9yjPohY7OU F7J3eKBTzp25AJ42BmtSd3pvm5ldmognWF3Trhp+GYkAlQMFEDe3O8IWkDf+zvyS FQEBAfkD/3GG5UgJj18UhYmh1gfjIlDcPAeqMwSytEHDENmHC+vlZQ/p0mT9tPiW tp34io54mwr+bLPN8l6B5GJNkbGvH6M+mO7R8Lj4nHL6pyAv3PQr83WyLHcaX7It Klj371/4yzKV6qpz43SGRK4MacLo2rNZ/dNej7lwPCtzCcFYwqkiiEYEEBECAAYF AjoaQqQACgkQx1KqMrDf94ArewCfWnTUDG5gNYkmHG4bYL8fQcizyA4An2eVo/n+ 3J2KRWSOhpAMsnMxtPbBmQGiBDnu9IERBACT8Y35+2vv4MGVKiLEMOl9GdST6MCk YS3yEKeueNWc+z/0Kvff4JctBsgs47tjmiI9sl0eHjm3gTR8rItXMN6sJEUHWzDP +Y0PFPboMvKx0FXl/A0dM+HFrruCgBlWt6FA+okRySQiliuI5phwqkXefl9AhkwR 8xocQSVCFxcwvwCglVcOQliHu8jwRQHxlRE0tkwQQI0D+wfQwKdvhDplxHJ5nf7U 8c/yE/vdvpN6lF0tmFrKXBUX+K7u4ifrZlQvj/81M4INjtXreqDiJtr99Rs6xa0S cZqITuZC4CWxJa9GynBED3+D2t1V/f8l0smsuYoFOF7Ib49IkTdbtwAThlZp8bEh ELBeGaPdNCcmfZ66rKUdG5sRA/9ovnc1krSQF2+sqB9/o7w5/q2qiyzwOSTnkjtB UVKn4zLUOf6aeBAoV6NMCC3Kj9aZHfA+ND0ehPaVGJgjaVNFhPi4x0e7BULdvgOo AqajLfvkURHAeSsxXIoEmyW/xC1sBbDkDUIBSx5oej73XCZgnj/inphRqGpsb+1n KFvF+rQoU3VTRSBQYWNrYWdlIFNpZ25pbmcgS2V5IDxidWlsZEBzdXNlLmRlPohi BBMRAgAiBQJA2AY+AhsDBQkObd+9BAsHAwIDFQIDAxYCAQIeAQIXgAAKCRCoTtro nIAKypCfAJ9RuZ6ZSV7QW4pTgTIxQ+ABPp0sIwCffG9bCNnrETPlgOn+dGEkAWeg KL+IRgQQEQIABgUCOnBeUgAKCRCeQOMQAAqrpNzOAKCL512FZvv4VZx94TpbA9lx yoAejACeOO1HIbActAevk5MUBhNeLZa/qM2JARUDBRA6cGBvd7LmAD0l09kBATWn B/9An5vfiUUE1VQnt+T/EYklES3tXXaJJp9pHMa4fzFa8jPVtv5UBHGee3XoUNDV wM2OgSEISZxbzdXGnqIlcT08TzBUD9i579uifklLsnr35SJDZ6ram51/CWOnnaVh UzneOA9gTPSr+/fT3WeVnwJiQCQ30kNLWVXWATMnsnT486eAOlT6UNBPYQLpUprF 5Yryk23pQUPAgJENDEqeU6iIO9Ot1ZPtB0lniw+/xCi13D360o1tZDYOp0hHHJN3 D3EN8C1yPqZd5CvvznYvB6bWBIpWcRgdn2DUVMmpU661jwqGlRz1F84JG/xe4jGu zgpJt9IXSzyohEJB6XG5+D0BuQINBDnu9JIQCACEkdBN6Mxf5WvqDWkcMRy6wnrd 9DYJ8UUTmIT2iQf07tRUKJJ9v0JXfx2Z4d08IQSMNRaq4VgSe+PdYgIy0fbj23Vi a5/gO7fJEpD2hd2f+pMnOWvH2rOOIbeYfuhzAc6BQjAKtmgR0ERUTafTM9Wb6F13 CNZZNZfDqnFDP6L12w3z3F7FFXkz07Rs3AIto1ZfYZd4sCSpMr/0S5nLrHbIvGLp 271hhQBeRmmoGEKO2JRelGgUJ2CUzOdtwDIKT0LbCpvaP8PVnYF5IFoYJIWRHqlE t5ucTXstZy7vYjL6vTP4l5xs+LIOkNmPhqmfsgLzVo0UaLt80hOwc4NvDCOLAAMG B/9g+9V3ORzw4LvO1pwRYJqfDKUq/EJ0rNMMD4N8RLpZRhKHKJUm9nNHLbksnlZw rbSTM5LpC/U6sheLP+l0bLVoq0lmsCcUSyh+mY6PxWirLIWCn/IAZAGnXb6Zd6Tt IJlGG6pqUN8QxGJYQnonl0uTJKHJENbI9sWHQdcTtBMc34gorHFCo1Bcvpnc1LFL rWn7mfoGx6INQjf3HGQpMXAWuSBQhzkazY6vaWFpa8bBJ+gKbBuySWzNm3rFtT5H RKMWpO+M9bHp4d+puY0L1YwN1OMatcMMpcWnZpiWiR83oi32+xtWUY2U7Ae38mMa g8zFbpeqPQUsDv9V7CAJ1dbriEwEGBECAAwFAkDYBnoFCQ5t3+gACgkQqE7a6JyA CspnpgCfRbYwxT3iq+9l/PgNTUNTZOlof2oAn25y0eGi0371jap9kOV6uq71sUuO =ypVs - -----END PGP PUBLIC KEY BLOCK----- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) iQEVAwUBRoPHkHey5gA9JdPZAQJtywf9GGsZhq6EfQUjCYhS8N7p18ZVSio4DS+L IPHUl319DPoXDNS2InWcNF7P2gacS7fm6XZ+XMyZid3d50bjAFRNnIlnFFRrAYQ6 2IByxo3DOV0y3fnwxQTZPoYL17ccCOWYh4BjDUBdRFsDwE9h9/Enj/UKeDtU8Dr0 2ZsLvO2O6pfhZM0nyL3eJ4j0typmv27YQSKpJGl5kt3rxeoOjNE72o2XY2aw7FNN T+ozFrPFLo2S1lSXAPdQBXpRXCO9eC+T57SQkf0hT+BRV47VbyJKKXrRJ1I0zQj6 S35kruLteVfkTrx9OnEnKC7Q2GGIm+jPdN/7VFyFQzmy4X6NfYPqKg== =CfrE -----END PGP SIGNATURE----- -- To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-security-announce+help@opensuse.org