Ceci est la liste des annonces de sécurité qui ont été faites pour la version stable actuelle de Frugalware
| Paquet: | openoffice.org |
| Date: | 2010-08-29 |
| Posté par: | Miklos Vajna |
| Version vulnérable: | 3.2.1-4 |
| Version non affectée: | 3.2.1-5haven1 |
| Entrée de suivi des bugs: | http://bugs.frugalware.org/task/4296 |
| CVEs: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2935 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2936 |
| Description: | Charlie Miller has discovered two vulnerabilities in OpenOffice.org Impress, which can be exploited by malicious people to compromise a user's system. 1) An integer truncation error when parsing certain content can be exploited to cause a heap-based buffer overflow via a specially crafted file. 2) A short integer overflow error when parsing certain content can be exploited to cause a heap-based buffer overflow via a specially crafted file. Successful exploitation of the vulnerabilities may allow execution of arbitrary code. |










