Bug 3957 - libreoffice missing security update for CVE-2011-2713
Summary: libreoffice missing security update for CVE-2011-2713
Status: RESOLVED DUPLICATE of bug 3830
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 1
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-12-31 00:06 CET by David Walser
Modified: 2011-12-31 00:18 CET (History)
0 users

See Also:
Source RPM: libreoffice-3.3.4.1-1.3.mga1.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2011-12-31 00:06:18 CET
Mandriva issued this advisory on November 11:
http://lists.mandriva.com/security-announce/2011-11/msg00017.php

The other CVE probably doesn't affect us since it says before 3.3.3.  MDV fixed it by upgrading to 3.4.3, but I'm not sure if that's what you want to do.
Comment 1 Manuel Hiebel 2011-12-31 00:13:31 CET
since libreoffice 3.4.4 is in testing I guess we can close this one

the also http://web.nvd.nist.gov/view/vuln/search-results?query=CVE-2011-2713&search_type=all&cves=on

oowriter in OpenOffice.org 3.3.0 and LibreOffice before 3.4.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted DOC file that triggers an out-of-bounds read in the DOC sprm parser
Comment 2 David Walser 2011-12-31 00:18:45 CET
This isn't really a duplicate, but the proposed update from Bug 3830 is new enough to fix this issue.

*** This bug has been marked as a duplicate of bug 3830 ***

Status: NEW => RESOLVED
Resolution: (none) => DUPLICATE


Note You need to log in before you can comment on or make changes to this bug.