summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Debian LibreOffice Maintainers [Sat, 28 Sep 2024 13:36:47 +0000 (13:36 +0000)]
debian-opt
Gbp-Pq: Name debian-opt.diff
Debian LibreOffice Maintainers [Sat, 28 Sep 2024 13:36:47 +0000 (13:36 +0000)]
no-check-if-root
Gbp-Pq: Name no-check-if-root.diff
Bastien Roucariès [Sat, 28 Sep 2024 13:36:47 +0000 (13:36 +0000)]
libreoffice (1:7.0.4-4+deb11u11) bullseye-security; urgency=medium
* LTS team upload
* Fix CVE-2024-7788:
Various file formats used by libreoffice are based on
the zip file format.
In cases of corruption of the underlying zip's central
directory, LibreOffice offers a "repair mode" which will
attempt to recover the zip file structure by scanning for
secondary local file headers in the zip to reconstruct
the document.
Prior to this fix, in the case of digitally signed zip
files, an attacker could construct a document which,
when repaired, reported a signature status not valid
for the recovered file.
Previously if verification failed the user could
choose to ignore the failure and enable the macros anyway.
Repair document mode has to be inherently tolerant,
so now in fixed versions all signatures are implied
to be invalid in recovery mode.
[dgit import unpatched libreoffice 1:7.0.4-4+deb11u11]
Bastien Roucariès [Sat, 28 Sep 2024 13:36:47 +0000 (13:36 +0000)]
Import libreoffice_7.0.4-4+deb11u11.debian.tar.xz
[dgit import tarball libreoffice 1:7.0.4-4+deb11u11 libreoffice_7.0.4-4+deb11u11.debian.tar.xz]
Rene Engelhard [Thu, 31 Dec 2020 12:00:06 +0000 (13:00 +0100)]
Import libreoffice_7.0.4.orig.tar.xz
[dgit import orig libreoffice_7.0.4.orig.tar.xz]
Rene Engelhard [Thu, 31 Dec 2020 12:00:06 +0000 (13:00 +0100)]
Import libreoffice_7.0.4.orig-helpcontent2.tar.xz
[dgit import orig libreoffice_7.0.4.orig-helpcontent2.tar.xz]
Rene Engelhard [Thu, 31 Dec 2020 12:00:06 +0000 (13:00 +0100)]
Import libreoffice_7.0.4.orig-translations.tar.xz
[dgit import orig libreoffice_7.0.4.orig-translations.tar.xz]