Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1661-1] New OpenOffice.org packages fix several vulnera

    From Martin Schulze@1:229/2 to All on Wed Oct 29 19:20:17 2008
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - -------------------------------------------------------------------------- Debian Security Advisory DSA 1661-1 [email protected] http://www.debian.org/security/ Martin Schulze October 29th, 2008 http://www.debian.org/security/faq
    - --------------------------------------------------------------------------

    Package : openoffice.org
    Vulnerability : several
    Problem type : local (remote)
    Debian-specific: no
    CVE IDs : CVE-2008-2237 CVE-2008-2238

    Several vulnerabilities have been discovered in the OpenOffice.org
    office suite:

    CVE-2008-2237

    The SureRun Security team discovered a bug in the WMF file parser
    that can be triggered by manipulated WMF files and can lead to
    heap overflows and arbitrary code execution.

    CVE-2008-2238

    An anonymous researcher working with the iDefense discovered a bug
    in the EMF file parser that can be triggered by manipulated EMF
    files and can lead to heap overflows and arbitrary code execution.

    For the stable distribution (etch) these problems have been fixed in
    version 2.0.4.dfsg.2-7etch6.

    For the unstable distribution (sid) these problems have been fixed in
    version 2.4.1-12.

    For the experimental distribution these problems have been fixed in
    version 3.0.0~rc3-1.

    We recommend that you upgrade your OpenOffice.org package.


    Upgrade Instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given at the end of this advisory:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org_2.0.4.dfsg.2-7etch6.dsc
    Size/MD5 checksum: 7250 f4f4de8e20c042084e99857478263f98
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org_2.0.4.dfsg.2-7etch6.diff.gz
    Size/MD5 checksum: 76919756 5be45e9198948abe84325d9b6dc5a3a1
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org_2.0.4.dfsg.2.orig.tar.gz
    Size/MD5 checksum: 232674922 2f1a5d92188639d3634bd6d1b1c29038

    Architecture independent components:

    http://security.debian.org/pool/updates/main/o/openoffice.org/broffice.org_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 475824 2e557668dfe736f9a81b8f55b7dae23e
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-common_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 27190074 24f455d5e1eb68d5dc202b323beb5d03
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-dev-doc_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 5553420 4f8b529afe806a5944a1ed8dfc35a81f
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-dtd-officedocument1.0_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 253618 084b50c33027f00b700617e01d75956d
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-filter-mobiledev_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 310412 1994317cfe10c4723604c8b1d708f2e3
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-cs_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 11870536 c4f313b500fbf264fcf462f807039d6d
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-da_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 11812004 0c455516cc2d6b35e18e8897738486ae
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-de_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 12667534 1b352d977566737094b8a87debc473d4
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-dz_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 15030182 d70043fcfeb893a899b410776e142830
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-en-gb_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 11359080 425bc302001a1c0ebe41fabd029917eb
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-en-us_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 11317436 ab66935ed29a79669bfb335484b9f909
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-en_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 215700 d5254e111acceac3f07d5ec9347a9ec7
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-es_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 12053756 10b15f3bf97d242a2ce9b28fa8640050
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-et_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 11975274 dfafc5f5a7ffe8a33a05ee6ed35c6d08
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-fr_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 12321070 0809a206b89f813a1b0f19bc97752514
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-hi-in_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 13158102 4077eb063f107e4ba7df48965711dc39
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-hu_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 12585742 b3fee955d5cb950466419ca2cde9c25c
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-it_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 12095272 51c1b02615933133753d5afb71deef73
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-ja_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 12778370 9c044a806c187420fe6e55207ebed8d8
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-km_2.0.4.dfsg.2-7etch6_all.deb
    Size/MD5 checksum: 14434052 99a56256395470d66762b32becc2aaba

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 156:01:15
    Calls: 12,092
    Files: 15,000
    Messages: 6,517,723

© >>> Magnum BBS <<<, 2026