Re: [tdf-discuss] security related information, CVE-2019-9850, CVE-2019-9851, CVE-2019-9852

2019-08-15 Thread Steve Edmonds
Had me confused. https://www.libreoffice.org/about-us/security/advisories/ Addressed in LibreOffice 6.2.6/6.3.0 CVE-2019-9850 Insufficient url validation allowing LibreLog

Re: [tdf-discuss] security related information, CVE-2019-9850, CVE-2019-9851, CVE-2019-9852

2019-08-15 Thread Jean-Baptiste Faure
Le 15/08/2019 à 12:52, Caolán McNamara a écrit : tl;dr; Upgrade to >= 6.2.6 or >= 6.0.0. I guess you mean ... or >= 6.3.0 Best regards. JBF There is a cluster of issues here. CVE-2019-9850 Insufficient url validation allowing LibreLogo script execution There was a way to encode the

[tdf-discuss] security related information, CVE-2019-9850, CVE-2019-9851, CVE-2019-9852

2019-08-15 Thread Caolán McNamara
tl;dr; Upgrade to >= 6.2.6 or >= 6.0.0. There is a cluster of issues here. CVE-2019-9850 Insufficient url validation allowing LibreLogo script execution There was a way to encode the script url that could bypass the fix of CVE-2019-9848 https://www.libreoffice.org/about-us/security/advisor