Re: About libreoffice CVE

2017-12-14 Thread Emilio Pozuelo Monfort
On 28/11/17 21:47, Antoine Beaupré wrote: > On 2017-11-24 11:58:42, Antoine Beaupré wrote: >> On 2017-11-24 11:49:34, Antoine Beaupré wrote: >>> I think I got a pretty good patchset now, attached. >> >> Well well... debdiff clearly doesn't like libreoffice - it crashes with: >> >> cp: erreur d'écri

Re: About libreoffice CVE

2017-11-28 Thread Antoine Beaupré
On 2017-11-24 11:58:42, Antoine Beaupré wrote: > On 2017-11-24 11:49:34, Antoine Beaupré wrote: >> I think I got a pretty good patchset now, attached. > > Well well... debdiff clearly doesn't like libreoffice - it crashes with: > > cp: erreur d'écriture de > './libreoffice_3.5.4+dfsg2.orig-transla

Re: About libreoffice CVE

2017-11-24 Thread Antoine Beaupré
On 2017-11-24 11:49:34, Antoine Beaupré wrote: > I think I got a pretty good patchset now, attached. Well well... debdiff clearly doesn't like libreoffice - it crashes with: cp: erreur d'écriture de './libreoffice_3.5.4+dfsg2.orig-translations.tar.xz': Aucun espace disponible sur le périphérique

Re: About libreoffice CVE

2017-11-24 Thread Antoine Beaupré
On 2017-11-24 10:14:20, Raphael Hertzog wrote: > Hi, > > On Thu, 23 Nov 2017, Antoine Beaupré wrote: >> > sal_uInt16 nLevelAnz; >> > rIn >> nLevelAnz; >> > if ( nLevelAnz > 5 ) >> > { >> > OSL_FAIL( "PPTStyleSheet::Ppt-TextStylesheet h

Re: About libreoffice CVE

2017-11-24 Thread Raphael Hertzog
Hi, On Thu, 23 Nov 2017, Antoine Beaupré wrote: > > sal_uInt16 nLevelAnz; > > rIn >> nLevelAnz; > > if ( nLevelAnz > 5 ) > > { > > OSL_FAIL( "PPTStyleSheet::Ppt-TextStylesheet hat mehr als 5 > > Ebenen! (SJ)" ); > > n

Re: About libreoffice CVE

2017-11-23 Thread Antoine Beaupré
On 2017-11-14 16:48:48, Raphael Hertzog wrote: > Hello Emilio, > > as the libreoffice entry is the oldest one without update[1] I decided > to take a look at the issues (even though it's assigned to you). > > For CVE-2017-CVE-2017-12607 I believe that wheezy is not affected as the patch > shown bel

Re: About libreoffice CVE

2017-11-16 Thread Raphael Hertzog
Hi, On Thu, 16 Nov 2017, Emilio Pozuelo Monfort wrote: > Well, it's there... > > libreoffice (Emilio Pozuelo) > NOTE: regression update, see: > NOTE: https://lists.debian.org/debian-lts/2017/05/msg00012.html Argh, sorry, I did not even check the entry... I only checked the output of bin/revi

Re: About libreoffice CVE

2017-11-16 Thread Emilio Pozuelo Monfort
On 16/11/17 09:39, Raphael Hertzog wrote: > On Tue, 14 Nov 2017, Emilio Pozuelo Monfort wrote: >> Yes, that was added back then due to a regression with the fix for >> https://security-tracker.debian.org/tracker/CVE-2017-3157 > > When you add an entry back for some reason, please document that > r

Re: About libreoffice CVE

2017-11-16 Thread Raphael Hertzog
On Tue, 14 Nov 2017, Emilio Pozuelo Monfort wrote: > Yes, that was added back then due to a regression with the fix for > https://security-tracker.debian.org/tracker/CVE-2017-3157 When you add an entry back for some reason, please document that reason... this entry in dla-needed.txt is useless if

Re: About libreoffice CVE

2017-11-14 Thread Emilio Pozuelo Monfort
On 14/11/17 17:02, Moritz Mühlenhoff wrote: > On Tue, Nov 14, 2017 at 04:48:48PM +0100, Raphael Hertzog wrote: >> Package: libreoffice >> Claimed-By: Emilio Pozuelo >> Claimed-Date: 2017-05-31 17:29 (166 days ago) > > There's some data error, CVE-2017-12607 and CVE-2017-12608 were only > disclosed

Re: About libreoffice CVE

2017-11-14 Thread Moritz Mühlenhoff
On Tue, Nov 14, 2017 at 04:48:48PM +0100, Raphael Hertzog wrote: > Package: libreoffice > Claimed-By: Emilio Pozuelo > Claimed-Date: 2017-05-31 17:29 (166 days ago) There's some data error, CVE-2017-12607 and CVE-2017-12608 were only disclosed on Oct 27. Cheers, Moritz

About libreoffice CVE

2017-11-14 Thread Raphael Hertzog
Hello Emilio, as the libreoffice entry is the oldest one without update[1] I decided to take a look at the issues (even though it's assigned to you). For CVE-2017-12607 I believe that wheezy is not affected as the patch shown below merely ensures that nLevelAnz does not overflow nMaxPPTLevels (=