Please note that OpenOffice.org version 2.4, released on 27th March, fixed a number of security vulnerabilities. To our knowledge, none of these has been exploited; however, in accordance with industry best practice, we recommend all users upgrade to 2.4.
This information was withheld intially to ensure that all the products derived from the OpenOffice.org codebase had time to include these security fixes before the public announcement of the vulnerabilities.
#Manipulated ODF text documents containing XForms can lead to heap overflows and arbitrary code execution
#Manipulated Quattro Pro files can lead to heap overflows and arbitrary code execution
#Manipulated EMF files can lead to heap overflows and arbitrary code execution
#Manipulated OLE files can lead to heap overflows and arbitrary code execution
ils n'ont pas annoncé ces soucis à la sortie de OpenOffice 2.4 mais bien bien après (à tort ou à raison mais ce n'est pas la question ici)
> Ce qui me gène énormément dans cette histoire, c'est l'attitude devs Debian qui cherche à discréditer tout le monde (upstream et autres distributions) au lieu d'assumer simplement leur responsabilité et faire profil bas.
[^] # Re: Mise en perspéctive
Posté par Gniarf . En réponse à la dépêche Découverte d'une faille de sécurité critique dans OpenSSL de Debian. Évalué à 4.
http://www.openoffice.org/news/index.html
Security update
Please note that OpenOffice.org version 2.4, released on 27th March, fixed a number of security vulnerabilities. To our knowledge, none of these has been exploited; however, in accordance with industry best practice, we recommend all users upgrade to 2.4.
This information was withheld intially to ensure that all the products derived from the OpenOffice.org codebase had time to include these security fixes before the public announcement of the vulnerabilities.
#Manipulated ODF text documents containing XForms can lead to heap overflows and arbitrary code execution
#Manipulated Quattro Pro files can lead to heap overflows and arbitrary code execution
#Manipulated EMF files can lead to heap overflows and arbitrary code execution
#Manipulated OLE files can lead to heap overflows and arbitrary code execution
ils n'ont pas annoncé ces soucis à la sortie de OpenOffice 2.4 mais bien bien après (à tort ou à raison mais ce n'est pas la question ici)
> Ce qui me gène énormément dans cette histoire, c'est l'attitude devs Debian qui cherche à discréditer tout le monde (upstream et autres distributions) au lieu d'assumer simplement leur responsabilité et faire profil bas.
je n'ai pas lu ça du tout.