Otklonjen je propust otkriven u radu programskog paketa libreoffice. Udaljeni napadač je mogao iskoristiti spomenuti nedostatak za izvođenje DoS napada i pokretanje proizvoljnog programskog koda.
Propust je posljedica višestrukih preljeva međuspremnika u dijelu koda namijenjenom parsiranju enkripcijskih oznaka u XML manifestu.
Posljedica:
Udaljeni napadač može iskoristiti navedeni nedostatak za DoS napad ili izvršavanje proizvoljnog programskog koda putem posebno oblikovane Open Document Text (.odt) datoteke.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-11402
2012-08-02 10:50:55
--------------------------------------------------------------------------------
Name : libreoffice
Product : Fedora 16
Version : 3.4.5.2
Release : 18.fc16
URL : http://www.documentfoundation.org/develop
Summary : Free Software Productivity Suite
Description :
LibreOffice is an Open Source, community-developed, office productivity suite.
It includes the key desktop applications, such as a word processor,
spreadsheet, presentation manager, formula editor and drawing program, with a
user interface and feature set similar to other office suites. Sophisticated
and flexible, LibreOffice also works transparently with a variety of file
formats, including Microsoft Office File Formats.
--------------------------------------------------------------------------------
Update Information:
Multiple heap-based buffer overflow flaws were found in the XML manifest
encryption tag parsing code of LibreOffice. An attacker could create a
specially-crafted file in the Open Document Format for Office Applications (ODF)
format which when opened could cause arbitrary code execution.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Aug 1 2012 CaolÄ
Posljednje sigurnosne preporuke