Re: CVE-2012-0037: OpenOffice.org data leakage vulnerability

2012-04-29 Thread NoOp
On 04/29/2012 01:42 PM, Rob Weir wrote: > On Sun, Apr 29, 2012 at 4:14 PM, Ariel Constenla-Haile ... >> >> The good news is that replacing the old library with the patched library >> solves the crash, and does not reproduce the vulnerability issue. >> >> I am not sure if anyone has been able to rep

Re: CVE-2012-0037: OpenOffice.org data leakage vulnerability

2012-04-29 Thread Ariel Constenla-Haile
On Sun, Apr 29, 2012 at 05:11:30PM -0400, Rob Weir wrote: > >> > I am not sure if anyone has been able to reproduce the issue on Linux > >> > with OOo 3.3. May be we can give you the file to test it, it would be > >> > nice to have someone else testing it. If someone knows we are able to do > >> >

Re: CVE-2012-0037: OpenOffice.org data leakage vulnerability

2012-04-29 Thread Rob Weir
On Sun, Apr 29, 2012 at 5:09 PM, Ariel Constenla-Haile wrote: > On Sun, Apr 29, 2012 at 04:42:22PM -0400, Rob Weir wrote: >> >> >> The library is inside the following package: >> >> >> 64 bits: ooobasis3.4-core05_3.4.0-1_amd64.deb >> >> >> 32 bits: ooobasis3.4-core05_3.4.0-1_i386.deb >> >> > >> >>

Re: CVE-2012-0037: OpenOffice.org data leakage vulnerability

2012-04-29 Thread Ariel Constenla-Haile
On Sun, Apr 29, 2012 at 04:42:22PM -0400, Rob Weir wrote: > >> >> The library is inside the following package: > >> >> 64 bits: ooobasis3.4-core05_3.4.0-1_amd64.deb > >> >> 32 bits: ooobasis3.4-core05_3.4.0-1_i386.deb > >> > > >> > Excellent! Got them both and so far nothing has blown up in 3.3.0 (

Re: CVE-2012-0037: OpenOffice.org data leakage vulnerability

2012-04-29 Thread Rob Weir
On Sun, Apr 29, 2012 at 4:14 PM, Ariel Constenla-Haile wrote: > Hi Gary, > > On Sun, Apr 29, 2012 at 12:24:11PM -0700, NoOp wrote: >> On 04/26/2012 01:36 PM, NoOp wrote: >> > On 04/24/2012 03:50 AM, Ariel Constenla-Haile wrote: >> ... >> >> >> >> The library is inside the following package: >> >>

Re: CVE-2012-0037: OpenOffice.org data leakage vulnerability

2012-04-29 Thread Ariel Constenla-Haile
Hi Gary, On Sun, Apr 29, 2012 at 12:24:11PM -0700, NoOp wrote: > On 04/26/2012 01:36 PM, NoOp wrote: > > On 04/24/2012 03:50 AM, Ariel Constenla-Haile wrote: > ... > >> > >> The library is inside the following package: > >> 64 bits: ooobasis3.4-core05_3.4.0-1_amd64.deb > >> 32 bits: ooobasis3.4-c

Re: CVE-2012-0037: OpenOffice.org data leakage vulnerability

2012-04-29 Thread NoOp
On 04/26/2012 01:36 PM, NoOp wrote: > On 04/24/2012 03:50 AM, Ariel Constenla-Haile wrote: ... >> >> The library is inside the following package: >> 64 bits: ooobasis3.4-core05_3.4.0-1_amd64.deb >> 32 bits: ooobasis3.4-core05_3.4.0-1_i386.deb > > Excellent! Got them both and so far nothing has bl