Artix Linux Forum

Artix Linux => Package management => Topic started by: dreieck on 17 May 2024, 18:22:49

Title: Libreoffice-still: Security issue, needs update to version 7.6.7 in the repos.
Post by: dreieck on 17 May 2024, 18:22:49
Due to a security issue in LibreOffice (https://www.heise.de/news/LibreOffice-Falscher-Klick-kann-zur-Ausfuehrung-von-Schadcode-fuehren-9719334.html), I think you (package maintainer of libreoffice-still should quickly update libreoffice-still in the repositories from current version 7.6.6 to new upstrean release 7.6.7 (skipping the "gremlins" phase to give users the version where the security issue is fixed)
Title: Re: Libreoffice-still: Security issue, needs update to version 7.6.7 in the repos.
Post by: Artist on 18 May 2024, 02:01:25
that is not an authorative source
there's no CVE or security issue mentioned at https://wiki.documentfoundation.org/Releases/7.6.7/RC1
Title: Re: Libreoffice-still: Security issue, needs update to version 7.6.7 in the repos.
Post by: dreieck on 18 May 2024, 10:04:34
there's no CVE or security issue mentioned at https://wiki.documentfoundation.org/Releases/7.6.7/RC1 (https://wiki.documentfoundation.org/Releases/7.6.7/RC1)
If you need to be provided information by LibreOffice themselves, then see https://www.libreoffice.org/about-us/security/advisories/CVE-2024-3044:
Quote
Fixed in: LibreOffice 7.6.7/24.2.3
Title: Re: Libreoffice-still: Security issue, needs update to version 7.6.7 in the repos.
Post by: gavincc on 18 May 2024, 17:43:52
it's 7.6.6-4 in extra, and the same in galaxy, so at the mo., its up to date following the Arch version as packages generally do.  (flagged out of date and 7.6.6-5 is in testing by  the looks of it).
Title: Re: Libreoffice-still: Security issue, needs update to version 7.6.7 in the repos.
Post by: dreieck on 18 May 2024, 18:51:51
it's 7.6.6-4 in extra, and the same in galaxy, so at the mo., its up to date following the Arch version as packages generally do.  (flagged out of date and 7.6.6-5 is in testing by  the looks of it).
According to libreoffice, 7.6.6-x will not fix the issue (except if -4 backports the patch).

Anyway, I think security wise Artix should not only follow but also act by itself (also sometimes other packages are not directly followed).
Title: Re: Libreoffice-still: Security issue, needs update to version 7.6.7 in the repos.
Post by: dreieck on 20 May 2024, 13:02:55
Now it is at 7.6.7.
Title: Re: Libreoffice-still: Security issue, needs update to version 7.6.7 in the repos.
Post by: nous on 20 May 2024, 18:47:35
This "CVE", which literally reads "Graphic on-click binding allows unchecked script execution", falls into the same category as "I run random bash scripts I download from keygen sites, as root in production servers". Let's not make it such a big deal.