Login
Login-Name Passwort


 
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in LibreOffice
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in LibreOffice
ID: DSA-3236-1
Distribution: Debian
Plattformen: Debian wheezy, Debian jessie
Datum: Sa, 25. April 2015, 15:01
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1774

Originalnachricht

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3236-1 security@debian.org
http://www.debian.org/security/ Moritz Muehlenhoff
April 25, 2015 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : libreoffice
CVE ID : CVE-2015-1774

It was discovered that missing input sanitising in Libreoffice's filter
for HWP documents may result in the execution of arbitrary code if a
malformed document is opened.

For the oldstable distribution (wheezy), this problem has been fixed in
version 1:3.5.4+dfsg2-0+deb7u4.

For the stable distribution (jessie), this problem has been fixed in
version 1:4.3.3-2+deb8u1.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your libreoffice packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJVO39VAAoJEBDCk7bDfE42gacP+wWENf5x88cO1SPpA3Jgpfav
6FylLJBl046ZI9pKUDwVOQvzSr5XdVNXg5oDmCyY29Ej3qOlSNd5RcYmB3EQdYS3
swCwndpyTnNdKCOjpEbbT7YB8wl9fhe4+/Iassj6tFnQGvXxa5ItJAqWJPpyaXSM
N+u6eZqItBhDdFmKcUL9TG0KSLYKJ7ND0odj7kr2P5Sf00ublsoMfNKCzekjba61
4bl9/7ieOZttU2SVRr8hNjtgJckQRW06hm1PuvxipuSOYGH16BhbQ8GwAnBP6gK0
Fgd9TpRbUsQyx/fKnhy/5kdRgDNpyF2wEfVMSffBXH7bpxk6z958RJwBJ7PEgqQ/
LNYJa1tgHHG6GAhKe9mpZttcSPwddzh1x65DIekLmVSWiJMEKMnHmKQzNgxLGSyM
fYch0hYTgq84+87IG9Me7IAJT7LHg9ZWeN8mZE9eqrybGX0Jp0eZaunKAqOzJv/Z
YsX2/+AKWYKudMss78po/lpaCt/xLHR+4X8WSy40My+LClv5gt3WsrbH21rcw8ov
5o0orcB5l1XWDawwTLlg4QQBWI5+qUqJCM+WbvxEL2Ao70FKBMOM9Jq+3Rj3l4ep
ano3nW357JW+SZe42A+COBdO68G0PzC8LSUq774ALQ/FMoClFWjRuk/OzRpYcxL7
pVaD4TXvlbVUtjGu/h+S
=6eYI
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact
listmaster@lists.debian.org
Archive: https://lists.debian.org/20150425115046.GA30722@pisco.westfalen.local
Pro-Linux
Traut euch!
Neue Nachrichten
Werbung