Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 2099-1] New OpenOffice.org packages fix arbitrary code

    From Martin Schulze@1:229/2 to All on Mon Aug 30 11:30:03 2010
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - -------------------------------------------------------------------------- Debian Security Advisory DSA 2099-1 [email protected] http://www.debian.org/security/ Martin Schulze August, 30th, 2010 http://www.debian.org/security/faq
    - --------------------------------------------------------------------------

    Package : openoffice.org
    Vulnerability : buffer overflows
    Problem type : local (remote)
    Debian-specific: no
    CVE ID : CVE-2010-2935 CVE-2010-2936

    Charlie Miller has discovered two vulnerabilities in OpenOffice.org
    Impress, which can be exploited by malicious people to compromise a
    user's system and execute arbitrary code.

    1) An integer truncation error when parsing certain content can be
    exploited to cause a heap-based buffer overflow via a specially
    crafted file.

    2) A short integer overflow error when parsing certain content can
    be exploited to cause a heap-based buffer overflow via a specially
    crafted file.

    For the stable distribution (lenny) these problems have been fixed in
    version 2.4.1+dfsg-1+lenny8.

    For the testing (squeeze) and unstable (sid) distributions these
    problems have been fixed in version 3.2.1-6.

    We recommend that you upgrade your openoffice.org packages.


    Upgrade Instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given at the end of this advisory:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org_2.4.1+dfsg-1+lenny8.dsc
    Size/MD5 checksum: 9765 793b58587b5d623aba852b8e531a78e1
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org_2.4.1+dfsg-1+lenny8.diff.gz
    Size/MD5 checksum: 84250778 4edcc6ebc5685177cfcafbdd586dfbd6
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org_2.4.1+dfsg.orig.tar.gz
    Size/MD5 checksum: 278867131 152a6c5b8e1b4e042ec027cca964e443

    Architecture independent components:

    http://security.debian.org/pool/updates/main/o/openoffice.org/broffice.org_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 518692 a7b5f357da74d846affaea87451f579b
    http://security.debian.org/pool/updates/main/o/openoffice.org/libuno-cli-basetypes1.0-cil_1.0.10.0+OOo2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 276872 c0b8c37ce124b8aaf6a0530b2a3f0afd
    http://security.debian.org/pool/updates/main/o/openoffice.org/libuno-cli-cppuhelper1.0-cil_1.0.13.0+OOo2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 274104 278acdf21f1c46707546239ee7ed782e
    http://security.debian.org/pool/updates/main/o/openoffice.org/libuno-cli-types1.1-cil_1.1.13.0+OOo2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 490208 d4eaa0cfb1705e0cffef0d0dcf3f980b
    http://security.debian.org/pool/updates/main/o/openoffice.org/libuno-cli-ure1.0-cil_1.0.13.0+OOo2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 275560 54bf60c3fb71f853dcf880466699b92d
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-common_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 14591534 b02d98e9557056e74eaec79db1a61f08
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-dev-doc_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 6048734 8eef7f1fdc87862ac7712cdd3d65f404
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-dtd-officedocument1.0_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 311734 8738c80ef738295d51e3b65713a079c4
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-emailmerge_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 277714 77bbe3ef1f841f05aa4e2f7abffb1dd0
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-filter-mobiledev_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 366462 81db0f315ca3a23525e252a3dc52172e
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-cs_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 13217194 fbde34ad032e3c543216580bc3d54663
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-da_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 13127816 e3714c2dddc05c9e5cb6de96f04906dc
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-de_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 14012038 762edfcebf6d22e90aa160bf0c7fe33c
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-dz_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 16925898 b1636e7c7320856f83444d142d6807f9
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-en-gb_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 12489888 58814b6b79cb451b5486d7c369b15673
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-en-us_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 12533356 e8204fbf8791f63b2979b76b71f89a5b
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-es_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 13518348 411f4a7afd55c780db12967018ee1cd0
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-et_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 13304222 18697145c68fbc336d87c91189a0e48c
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-eu_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 13277974 2ef2c6f9363bcea034c4e5323c255fff
    http://security.debian.org/pool/updates/main/o/openoffice.org/openoffice.org-help-fr_2.4.1+dfsg-1+lenny8_all.deb
    Size/MD5 checksum: 13703416 897aed403277119a57e6e5f6635f1349

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 714
    Nodes: 16 (2 / 14)
    Uptime: 141:06:46
    Calls: 12,087
    Files: 14,998
    Messages: 6,517,434

© >>> Magnum BBS <<<, 2026