Path to this page:
Subject: CVS commit: [pkgsrc-2009Q2] pkgsrc/misc/openoffice2
From: Matthias Scheler
Date: 2009-09-14 00:32:50
Message id: 20090913223250.9A51A175D0@cvs.netbsd.org
Log Message:
Pullup ticket #2890 - requested by hira
openoffice2: security update
Revisions pulled up:
- misc/openoffice2/Makefile 1.74 via patch
- misc/openoffice2/distinfo 1.55 via patch
- misc/openoffice2/patches/patch-ga 1.1
- misc/openoffice2/patches/patch-gb 1.1
- misc/openoffice2/patches/patch-gc 1.1
---
Module Name: pkgsrc
Committed By: hira
Date: Sun Sep 13 03:54:14 UTC 2009
Modified Files:
pkgsrc/misc/openoffice2: Makefile distinfo
Added Files:
pkgsrc/misc/openoffice2/patches: patch-ga patch-gb patch-gc
Log Message:
Update to 2.4.3. This is bug fix release. It fixes the following
security vulnerabilities.
* CVE-2009-0200/CVE-2009-0201: Manipulated Microsoft Word files can
lead to heap overflows and arbitrary code execution
* CVE-2009-2414/CVE-2009-2416: Manipulated XML documents can lead to
arbitrary code execution
Release notes: http://development.openoffice.org/releases/2.4.3.html
- Fix getline() problem (patches from misc/openoffice3/patches).
- Use internal neon (9 patches are required to use external neon).
- Use internal openssl for internal neon.
- Disable VBA extension (enabling this causes build error).
Files: