Return-Path: X-Original-To: apmail-incubator-ooo-dev-archive@minotaur.apache.org Delivered-To: apmail-incubator-ooo-dev-archive@minotaur.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 56DD6979C for ; Wed, 5 Oct 2011 21:00:55 +0000 (UTC) Received: (qmail 60910 invoked by uid 500); 5 Oct 2011 21:00:55 -0000 Delivered-To: apmail-incubator-ooo-dev-archive@incubator.apache.org Received: (qmail 60817 invoked by uid 500); 5 Oct 2011 21:00:55 -0000 Mailing-List: contact ooo-dev-help@incubator.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: ooo-dev@incubator.apache.org Delivered-To: mailing list ooo-dev@incubator.apache.org Received: (qmail 60809 invoked by uid 99); 5 Oct 2011 21:00:55 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 05 Oct 2011 21:00:55 +0000 X-ASF-Spam-Status: No, hits=0.0 required=5.0 tests=FREEMAIL_FROM,RCVD_IN_DNSWL_NONE,SPF_PASS,T_TO_NO_BRKTS_FREEMAIL X-Spam-Check-By: apache.org Received-SPF: pass (athena.apache.org: domain of dave2wave@comcast.net designates 76.96.27.227 as permitted sender) Received: from [76.96.27.227] (HELO qmta12.emeryville.ca.mail.comcast.net) (76.96.27.227) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 05 Oct 2011 21:00:49 +0000 Received: from omta18.emeryville.ca.mail.comcast.net ([76.96.30.74]) by qmta12.emeryville.ca.mail.comcast.net with comcast id h0w11h00C1bwxycAC90Prv; Wed, 05 Oct 2011 21:00:23 +0000 Received: from [192.168.1.7] ([67.180.51.144]) by omta18.emeryville.ca.mail.comcast.net with comcast id h96S1h00i36gVt78e96S15; Wed, 05 Oct 2011 21:06:27 +0000 Subject: Re: Vulnerability fixed in LibreOffice Mime-Version: 1.0 (Apple Message framework v1084) Content-Type: text/plain; charset=us-ascii From: Dave Fisher In-Reply-To: <00ed01cc839c$70bd9030$5238b090$@apache.org> Date: Wed, 5 Oct 2011 14:00:28 -0700 Cc: Content-Transfer-Encoding: quoted-printable Message-Id: References: <00e601cc8396$a4eeaca0$eecc05e0$@apache.org> <6AA74BAB-B366-4B88-9472-D78FA94DD599@webmink.com> <00ed01cc839c$70bd9030$5238b090$@apache.org> To: ooo-dev@incubator.apache.org X-Mailer: Apple Mail (2.1084) On Oct 5, 2011, at 1:21 PM, Dennis E. Hamilton wrote: > [bcc: ooo-security@i.a.o, tdf-security@l.df.o] >=20 > That information concerning an ApacheOOo representative on=20 > securityteam@openoffice.org is apparently inaccurate. Or=20 > else there is a breakdown in the vulnerability being=20 > communicated to ApacheOOo. Rather unfortunate as that seemed to be one area of co-operation. IMHO - It would make sense for someone to either immediately shutdown = securityteam@openoffice.org or make it forward to ooo-security@i.a.o. If INFRA-3898 were completed we might have a chance until then ... Regards, Dave >=20 > However, since the patch has been made, the CVE and supporting > details should now be available somewhere public. Also, the > report refers to "some additional security patches and fixes" > without mention of any CVEs. It would be good to know what=20 > that is about. >=20 > The LibreOffice 3.4.3 Release Notes provide no clue: > < http://wiki.documentfoundation.org/Releases/3.4.3_info_about_fixes>. >=20 > I did find two CVEs here: > < http://www.libreoffice.org/advisories/> >=20 > The CVE list has not been updated yet: > < http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2011-2713> >=20 > I trust this is the last time that either of our projects learn about=20= > something like this in a press release. >=20 >=20 > - Dennis >=20 > -----Original Message----- > From: Simon Phipps [mailto:simon@webmink.com]=20 > Sent: Wednesday, October 05, 2011 12:49 > To: ooo-dev@incubator.apache.org > Subject: Re: Vulnerability fixed in LibreOffice >=20 > I've investigated and I am informed by one of the LO developers: >> The initial report was sent to securityteam@openoffice.org on >> 25-07-2011, the assigned CVE id was cc'ed there somewhat later on. I >> posted the 5 patches which in combination would fix it to the list as >> well. I was informed an ApacheOOo representative had joined the list. >=20 >=20 > On 5 Oct 2011, at 20:40, Dennis E. Hamilton wrote: >=20 >> [bcc to ooo-security@i.a.o] >>=20 >> It is difficult to tell from a press release what the details of = security fixes are. =20 >>=20 >>=20 >> -----Original Message----- >> From: FR web forum [mailto:oooforum@free.fr]=20 >> Sent: Wednesday, October 05, 2011 10:15 >>=20 >> Good morning, >>=20 >> TDF has published a fix for LibO: http://wp.me/p1byPE-bQ >>=20 >> Do you know if OOo is impacted too? >>=20 >> Thank you >>=20 >=20