U radu programskog paketa openoffice.org oočeni su višestruki preljevi međuspremika koje zlonamjerni korisnik može iskoristiti za rušenje aplikacije ili pokretanje proizvoljnog programskog koda.
Paket:
openoffice.org 1.x
Operacijski sustavi:
Debian Linux 6.0 (squeeze), Debian Linux sid (unstable), Debian Linux wheezy (testing)
Propusti su posljedica višestrukih prekoračenja spremnika gomile.
Posljedica:
Korištenjem posebno oblikovanih Open Document Text (.odt) datoteka, zlonamjerni korisnik može iskoristiti navedeni propust za pokretanje proizvoljnog koda ili izvođenje DoS napada.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-2520-1 Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://www.debian.org/security/ Yves-Alexis Perez
August 01, 2012 http://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : openoffice.org
Vulnerability : Multiple heap-based buffer overflows
Problem type : local
Debian-specific: no
CVE ID : CVE-2012-2665
Debian Bug :
Timo Warns from PRE-CERT discovered multiple heap-based buffer overflows in
OpenOffice.org, an office productivity suite. The issues lies in the XML
manifest encryption tag parsing code. Using specially crafted files, an
attacker can cause application crash and could cause arbitrary code execution.
For the stable distribution (squeeze), this problem has been fixed in
version 3.2.1-11+squeeze7.
openoffice.org package has been replaced by libreoffice in testing (wheezy) and
unstable (sid) distributions.
For the testing distribution (wheezy), this problem has been fixed in
version 1:3.5.4-7.
For the unstable distribution (sid), this problem has been fixed in
version 1:3.5.4-7.
We recommend that you upgrade your openoffice.org packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQIcBAEBCgAGBQJQGtV4AAoJEDBVD3hx7wuokBsP/3t05CwoFnMJJMNq6XhkvyPP
dSRYYdNQA5XH6Pd1YQH7h6XVZKjeQafY1SIpr1zrbFTl3rJkuDR817HhLdkoZZHC
8JbHvp9mzUbT8Y6Hhbq/Cc+5BaPtfiOHhymF1BJQAlO+O2KlD4MuZsVGlFmUuV7v
KJtTyJT7tHx3ntmqylamH1+9nDzKXGplsRddZFFWmS9N0cZoji3Nh45G6nN94sdr
OUqsNUC2lFqEgldUjyeRc5QL2uINM3+NPcU9zpdMNBYDm5DZBxDOeEU/asdBfgPs
mjX4vbXsPiaxPL78pvfIhz/fTE68pkCebdNZC41d+mkqpdJIq0vGvYHlZ2Lz0E+T
BhwBRw1oesz08DA6+dy/beIeIL8ASAvVE/eQdzfCVMLMqLkQKClj+XybKv2/LT+l
UN70miF9eeosAAB70208G+N4DR3QYv3s3h7ZBHfJJC/1UUBllfoiJHpb+QpZhnyI
HwwrdDvMT/PmmN+3IL9aa6hWKyJuV7lX+Rq/jRzEZB+w7EcR145vSCM68lpdjZ3X
cVQaT/iw243j4koBm865SzCRKfKayWfvAa8vj2PI/I79MHNcfuu+d6brDVDW6m02
gQAwjT8UVyfwtNwovVtxi4csjBsX/cByFHQs6nyFdmjlbaN0xq0As40MgzZAdSXl
IKI70drvK8OCEexPfzf9
=ymEK
-----END PGP SIGNATURE-----
--
To UNSUBSCRIBE, email to Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
with a subject of "unsubscribe". Trouble? Contact Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Archive: http://lists.debian.org/Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Posljednje sigurnosne preporuke