Security update for OpenOffice.org based in 3.2.0

Bug #521692 reported by Joe le Kiffeur
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
openoffice.org (Ubuntu)
Fix Released
Medium
Unassigned
Hardy
Fix Released
Medium
Unassigned
Intrepid
Fix Released
Medium
Unassigned
Jaunty
Fix Released
Medium
Unassigned
Karmic
Fix Released
Medium
Unassigned
Lucid
Fix Released
Medium
Unassigned

Bug Description

Binary package hint: openoffice.org

Hi!

(Please don't byte me :) : my level in English is bad)

The newer OpenOffice.org has 6 security fixes and this bulletin ( http://www.openoffice.org/security/bulletin.html ) recommend to update to 3.2.0. This also include the default 3.1.1 version in Karmic.
Please update before Lucid Lynx.

3.2.0 security fixes :

* CVE-2006-4339: Potential vulnerability from 3rd party libxml2 libraries
* CVE-2009-0217: Potential vulnerability from 3rd party libxmlsec libraries
* CVE-2009-2493: OpenOffice.org 3 for Windows bundles a vulnerable version of MSVC Runtime
* CVE-2009-2949: Potential vulnerability related to XPM file processing
* CVE-2009-2950: Potential vulnerability related to GIF file processing
* CVE-2009-3301/2: Potential vulnerability related to MS-Word document processing

Also, all version of Ubuntu with OpenOffice.org 3.x (3.0, 3.0.1, 3.1.0, 3.1.1) are affected.

Please consider it because the newer version seems the solution. I'm not sure the OpenOffice.org dev team wants to make a 3.1.2... :(.

Thanks.

EDIT: don't care about attached files beacause I used a crash report beacause lauchpad.net is non intuitive and difficult to report bugs (where to file anyone ?). Sorry for that.

Revision history for this message
Joe le Kiffeur (joelekiffeur) wrote :
description: updated
description: updated
description: updated
Changed in openoffice.org (Ubuntu):
status: New → Confirmed
Changed in openoffice.org (Ubuntu):
assignee: nobody → Joe le Kiffeur (joelekiffeur)
Kees Cook (kees)
Changed in openoffice.org (Ubuntu):
assignee: Joe le Kiffeur (joelekiffeur) → nobody
summary: - Security update in Karmic: OpenOffice.org must me updated to 3.2.0
+ Security update for OpenOffice.org based in 3.2.0
visibility: private → public
Changed in openoffice.org (Ubuntu Lucid):
status: Confirmed → Triaged
Changed in openoffice.org (Ubuntu Karmic):
status: New → Triaged
Changed in openoffice.org (Ubuntu Intrepid):
status: New → Triaged
Changed in openoffice.org (Ubuntu Jaunty):
status: New → Triaged
Changed in openoffice.org (Ubuntu Hardy):
status: New → Triaged
Revision history for this message
Kees Cook (kees) wrote :

This has been published in http://www.ubuntu.com/usn/USN-903-1

Changed in openoffice.org (Ubuntu Lucid):
status: Triaged → Fix Released
importance: Undecided → Medium
Changed in openoffice.org (Ubuntu Hardy):
status: Triaged → Fix Released
importance: Undecided → Medium
Changed in openoffice.org (Ubuntu Intrepid):
status: Triaged → Fix Released
importance: Undecided → Medium
Changed in openoffice.org (Ubuntu Jaunty):
status: Triaged → Fix Released
importance: Undecided → Medium
Changed in openoffice.org (Ubuntu Karmic):
status: Triaged → Fix Released
importance: Undecided → Medium
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.