-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3236-1 security@debian.org http://www.debian.org/security/ Moritz Muehlenhoff April 25, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libreoffice CVE ID : CVE-2015-1774 It was discovered that missing input sanitising in Libreoffice's filter for HWP documents may result in the execution of arbitrary code if a malformed document is opened. For the oldstable distribution (wheezy), this problem has been fixed in version 1:3.5.4+dfsg2-0+deb7u4. For the stable distribution (jessie), this problem has been fixed in version 1:4.3.3-2+deb8u1. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your libreoffice packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBAgAGBQJVO39VAAoJEBDCk7bDfE42gacP+wWENf5x88cO1SPpA3Jgpfav 6FylLJBl046ZI9pKUDwVOQvzSr5XdVNXg5oDmCyY29Ej3qOlSNd5RcYmB3EQdYS3 swCwndpyTnNdKCOjpEbbT7YB8wl9fhe4+/Iassj6tFnQGvXxa5ItJAqWJPpyaXSM N+u6eZqItBhDdFmKcUL9TG0KSLYKJ7ND0odj7kr2P5Sf00ublsoMfNKCzekjba61 4bl9/7ieOZttU2SVRr8hNjtgJckQRW06hm1PuvxipuSOYGH16BhbQ8GwAnBP6gK0 Fgd9TpRbUsQyx/fKnhy/5kdRgDNpyF2wEfVMSffBXH7bpxk6z958RJwBJ7PEgqQ/ LNYJa1tgHHG6GAhKe9mpZttcSPwddzh1x65DIekLmVSWiJMEKMnHmKQzNgxLGSyM fYch0hYTgq84+87IG9Me7IAJT7LHg9ZWeN8mZE9eqrybGX0Jp0eZaunKAqOzJv/Z YsX2/+AKWYKudMss78po/lpaCt/xLHR+4X8WSy40My+LClv5gt3WsrbH21rcw8ov 5o0orcB5l1XWDawwTLlg4QQBWI5+qUqJCM+WbvxEL2Ao70FKBMOM9Jq+3Rj3l4ep ano3nW357JW+SZe42A+COBdO68G0PzC8LSUq774ALQ/FMoClFWjRuk/OzRpYcxL7 pVaD4TXvlbVUtjGu/h+S =6eYI -----END PGP SIGNATURE-----