Subject: CVS commit: [pkgsrc-2009Q2] pkgsrc/misc/openoffice2
From: Matthias Scheler
Date: 2009-09-14 00:32:50
Message id: 20090913223250.9A51A175D0@cvs.netbsd.org

Log Message:
Pullup ticket #2890 - requested by hira
openoffice2: security update

Revisions pulled up:
- misc/openoffice2/Makefile			1.74 via patch
- misc/openoffice2/distinfo			1.55 via patch
- misc/openoffice2/patches/patch-ga		1.1
- misc/openoffice2/patches/patch-gb		1.1
- misc/openoffice2/patches/patch-gc		1.1
---
Module Name:	pkgsrc
Committed By:	hira
Date:		Sun Sep 13 03:54:14 UTC 2009

Modified Files:
	pkgsrc/misc/openoffice2: Makefile distinfo
Added Files:
	pkgsrc/misc/openoffice2/patches: patch-ga patch-gb patch-gc

Log Message:
Update to 2.4.3.  This is bug fix release.  It fixes the following
security vulnerabilities.

 * CVE-2009-0200/CVE-2009-0201: Manipulated Microsoft Word files can
   lead to heap overflows and arbitrary code execution
 * CVE-2009-2414/CVE-2009-2416: Manipulated XML documents can lead to
   arbitrary code execution

Release notes: http://development.openoffice.org/releases/2.4.3.html

 - Fix getline() problem (patches from misc/openoffice3/patches).
 - Use internal neon (9 patches are required to use external neon).
 - Use internal openssl for internal neon.
 - Disable VBA extension (enabling this causes build error).

Files:
RevisionActionfile
1.69.2.1modifypkgsrc/misc/openoffice2/Makefile
1.53.4.1modifypkgsrc/misc/openoffice2/distinfo
1.1.2.2addpkgsrc/misc/openoffice2/patches/patch-ga
1.1.2.2addpkgsrc/misc/openoffice2/patches/patch-gb
1.1.2.2addpkgsrc/misc/openoffice2/patches/patch-gc