[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249982

 
 

909

 
 

195748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2010:075 -- Mandriva openoffice.org

ID: oval:org.secpod.oval:def:300125Date: (C)2012-01-07   (M)2021-11-24
Class: PATCHFamily: unix




This updates provides a security update to the OpenOffice.org described as follow: OpenOffice"s xmlsec uses a bundled Libtool which might load .la file in the current working directory allowing local users to gain privileges via a Trojan horse file. For enabling such vulnerability xmlsec has to use --enable-crypto_dl building flag however it does not, although the fix keeps protected against this threat whenever that flag had been enabled . Addittionaly this update provides following bug fixes: OpenOffice.org is not properly configure to use the xdg-email functionality of the FreeDesktop standard . Template desktop icons are not properly set up then they are not presented under the context menu of applications like Dolphin . libia_ora-gnome is added as suggest as long as that package is needed for a better look . It is enabled a fallback logic to properly select an OpenOffice.org style whenever one is set up but that is not installed It is enabled the Firefox plugin for viewing OpenOffice.org documents inside browser.

Platform:
Mandriva Linux 2010.0
Product:
openoffice.org
Reference:
MDVSA-2010:075
CVE-2009-3736
CVE    1
CVE-2009-3736
CPE    1
cpe:/o:mandriva:linux:2010.0

© SecPod Technologies