Bug#913702: libwpd: CVE-2018-19208

2018-11-14 Thread Moritz Mühlenhoff
On Wed, Nov 14, 2018 at 09:50:19PM +0100, Salvatore Bonaccorso wrote: > Hi Rene, > > On Wed, Nov 14, 2018 at 09:22:04PM +0100, Rene Engelhard wrote: > > Hi, > > > > On Wed, Nov 14, 2018 at 08:19:05AM +0100, Salvatore Bonaccorso wrote: > > > [2] > > > https://src.fedoraproject.org/rpms/libwpd/blo

Bug#913702: libwpd: CVE-2018-19208

2018-11-14 Thread Salvatore Bonaccorso
Hi Rene, On Wed, Nov 14, 2018 at 09:22:04PM +0100, Rene Engelhard wrote: > Hi, > > On Wed, Nov 14, 2018 at 08:19:05AM +0100, Salvatore Bonaccorso wrote: > > [2] > > https://src.fedoraproject.org/rpms/libwpd/blob/e42834b844f3282d8ccb0889abf1b33f3f71e02f/f/0001-Resolves-rhbz-1643752-bounds-check-m

Bug#913702: libwpd: CVE-2018-19208

2018-11-14 Thread Rene Engelhard
Hi, On Wed, Nov 14, 2018 at 08:19:05AM +0100, Salvatore Bonaccorso wrote: > [2] > https://src.fedoraproject.org/rpms/libwpd/blob/e42834b844f3282d8ccb0889abf1b33f3f71e02f/f/0001-Resolves-rhbz-1643752-bounds-check-m_currentTable-ac.patch Will apply, thanks. > Please adjust the affected versions i

Bug#913702: libwpd: CVE-2018-19208

2018-11-13 Thread Salvatore Bonaccorso
Source: libwpd Version: 0.10.2-2 Severity: important Tags: upstream security Hi, The following vulnerability was published for libwpd. CVE-2018-19208[0]: | In libwpd 0.10.2, there is a NULL pointer dereference in the function | WP6ContentListener::defineTable in WP6ContentListener.cpp that will