Bug#1051474: libreoffice: Please add embeded code copies to embeded-code-copies on security tracker debian.tar.xz/tarballs

2023-09-10 Thread Moritz Muehlenhoff
On Sun, Sep 10, 2023 at 07:13:37AM +, Bastien Roucariès wrote: > Le dimanche 10 septembre 2023, 05:44:02 UTC Rene Engelhard a écrit : > > severity 1051474 important > > > > thanks > > > > Hi, > > > > Am 08.09.23 um 19:19 schrieb Bastien Roucariès: > > > Source: libreoffice > > > Severity: se

Bug#1005983: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: myspell Version: 1:3.0+pre3.1-24.2 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#875415: predictable /tmp file vulnerability while building libreoffice

2017-09-11 Thread Moritz Muehlenhoff
On Mon, Sep 11, 2017 at 10:55:39AM +0200, Helmut Grohne wrote: > Source: libreoffice > Version: 1:5.4.0-1 > Severity: important > Tags: security upstream > > Looking at a sample build log > (https://buildd.debian.org/status/fetch.php?pkg=libreoffice&arch=m68k&ver=1%3A5.4.1-1&stamp=1504466495&raw=0

Bug#864366: CVE-2017-9433

2017-06-07 Thread Moritz Muehlenhoff
Source: libmwaw Severity: grave Tags: security Please see https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9433 Cheers, Moritz

Bug#864207: CVE-2017-9432

2017-06-05 Thread Moritz Muehlenhoff
Source: libstaroffice Severity: important Tags: security Hi, please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9432 Patch is here: https://github.com/fosnola/libstaroffice/commit/2d6253c7a692a3d92785dd990fce7256ea05e794 Cheers, Moritz

Bug#771163: libreoffice: CVE-2014-9093

2014-11-27 Thread Moritz Muehlenhoff
Package: libreoffice Severity: grave Tags: security Justification: user security hole Hi, please see https://bugs.freedesktop.org/show_bug.cgi?id=86449 for the bug report with a reproducer (which also crashes the version in wheezy). 4.3 fix by Caolan: http://cgit.freedesktop.org/libreoffice/core/

Bug#728608: ooeclipseintegration: FTBFS: unsatisfiable B-D: openoffice.org-java-common

2014-04-16 Thread Moritz Muehlenhoff
On Mon, Nov 04, 2013 at 10:09:19AM +0100, Rene Engelhard wrote: > Hi, > > On Sun, Nov 03, 2013 at 03:41:56PM +0100, Andreas Beckmann wrote: > > # apt-get build-dep ooeclipseintegration > > Reading package lists... Done > > Building dependency tree > > Reading state information... Done > > E: Build

Bug#732380: libreoffice-writer: Vertical text alignment problem with Japanese text

2014-01-09 Thread Moritz Muehlenhoff
On Tue, Dec 17, 2013 at 09:52:59PM +0900, Osamu Aoki wrote: > Package: libreoffice-writer > Version: 1:4.1.3-1+b1 > Severity: normal > > The vertical text alignment always bothered me and made me use non-free > fonts. Problem seems to be in several places. > * libreoffice screen rendering > * l

Bug#656643: Hardened build flags

2012-01-24 Thread Moritz Muehlenhoff
On Tue, Jan 24, 2012 at 02:49:47AM +0100, Rene Engelhard wrote: > tag 656643 - patch > thanks > > Hi, > > On Fri, Jan 20, 2012 at 06:32:16PM +0100, Moritz Muehlenhoff wrote: > > attached you can find a patch against libreoffice from experimental > > to enable d

Bug#656643: Hardened build flags

2012-01-20 Thread Moritz Muehlenhoff
Source: libreoffice Severity: normal Tags: patch Hi Rene, attached you can find a patch against libreoffice from experimental to enable dpkg-buildflags for libreoffice (enabling hardened build flags for Wheezy). This should be backport-friendly for Squeeze, since dpkg-buildflags exists in Squeez

Bug#551068: CVE-2009-3569, CVE-2009-3570, CVE-2009-3571: multiple vulnerabilities

2009-11-24 Thread Moritz Muehlenhoff
severity 551068 normal thanks On Thu, Oct 15, 2009 at 05:55:01PM +0200, Giuseppe Iuculano wrote: > Rene Engelhard ha scritto: > > If you tell me how they should be fixed if no one ever knew about that > > except > > the VulnDisco Pack author... > > You are right, the details are unknown, but thi

Bug#304469: openoffice.org: Invalid range checking in DOC header parsing leading to possible heap overflow

2005-04-13 Thread Moritz Muehlenhoff
Package: openoffice.org Version: 1.1.3-8 Severity: grave Tags: security Justification: user security hole Lee Xioajun <[EMAIL PROTECTED]> reported an issue with invalid input checks in DOC header parsing, which can possibly be exploited with remote code execution. I'm including his advisory verbos

Missing dependancy

2002-07-02 Thread Moritz Muehlenhoff
Hi, I just tried to install the Open-Office-debs to review some presentation slides and I noticed a missing dependancy in the deb-spec file: My notebook is running without any kind of printing subsystem, while Open-Office depends on cupsys-bsd | lprng | lpr to run the installer. I think this shoul