[Full-disclosure] [SECURITY] [DSA 1270-1] New OpenOffice.org packages fix several vulnerabilities

Peter Besenbruch prb at lava.net
Tue Mar 20 21:22:04 GMT 2007


Martin Schulze wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> - --------------------------------------------------------------------------
> Debian Security Advisory DSA 1270-1                    security at debian.org
> http://www.debian.org/security/                             Martin Schulze
> March 20th, 2007                        http://www.debian.org/security/faq
> - --------------------------------------------------------------------------
> 
> Package        : openoffice.org
> Vulnerability  : several
> Problem type   : local (remote)
> Debian-specific: no
> CVE IDs        : CVE-2007-0002 CVE-2007-0238 CVE-2007-0239

....

> For the testing distribution (etch) these problems have been fixed in
> version 2.0.4.dfsg.2-6.
> 
> For the unstable distribution (sid) these problems have been fixed in
> version 2.0.4.dfsg.2-6.

Of course, it would be more helpful to have the actual, fixed, versions 
uploaded and available, when announcing that we should update.

-- 
Hawaiian Astronomical Society: http://www.hawastsoc.org
HAS Deepsky Atlas: http://www.hawastsoc.org/deepsky




Full-Disclosure is hosted and sponsored by Secunia.