You are here
Home > Preporuke > Ranjivost programskog paketa antiword

Ranjivost programskog paketa antiword

  • Detalji os-a: FED
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2014-16257
2014-12-04 05:22:07
——————————————————————————–

Name : antiword
Product : Fedora 19
Version : 0.37
Release : 17.fc19
URL : http://www.winfield.demon.nl/
Summary : MS Word to ASCII/Postscript converter
Description :
Antiword is a free MS-Word reader for Linux, BeOS and RISC OS. It converts
the documents from Word 6, 7, 97 and 2000 to ASCII and Postscript. Antiword
tries to keep the layout of the document intact.

——————————————————————————–
Update Information:

Security fix for CVE-2014-8123
——————————————————————————–
ChangeLog:

* Tue Dec 2 2014 Adrian Reber <adrian@lisas.de> – 0.37-17
– added patch for “CVE-2014-8123 antiword: buffer overflow of atPPSlist[].szName[]” (#1169665)
– fixed dates in changelog
* Fri Aug 15 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 0.37-16
– Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
* Sat Jun 7 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 0.37-15
– Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Sat Aug 3 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 0.37-14
– Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild
——————————————————————————–
References:

[ 1 ] Bug #1169665 – CVE-2014-8123 antiword: buffer overflow of atPPSlist[].szName[]
https://bugzilla.redhat.com/show_bug.cgi?id=1169665
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update antiword’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2014-16241
2014-12-04 05:21:21
——————————————————————————–

Name : antiword
Product : Fedora 20
Version : 0.37
Release : 17.fc20
URL : http://www.winfield.demon.nl/
Summary : MS Word to ASCII/Postscript converter
Description :
Antiword is a free MS-Word reader for Linux, BeOS and RISC OS. It converts
the documents from Word 6, 7, 97 and 2000 to ASCII and Postscript. Antiword
tries to keep the layout of the document intact.

——————————————————————————–
Update Information:

Security fix for CVE-2014-8123
——————————————————————————–
ChangeLog:

* Tue Dec 2 2014 Adrian Reber <adrian@lisas.de> – 0.37-17
– added patch for “CVE-2014-8123 antiword: buffer overflow of atPPSlist[].szName[]” (#1169665)
– fixed dates in changelog
* Fri Aug 15 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 0.37-16
– Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
* Sat Jun 7 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 0.37-15
– Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
——————————————————————————–
References:

[ 1 ] Bug #1169665 – CVE-2014-8123 antiword: buffer overflow of atPPSlist[].szName[]
https://bugzilla.redhat.com/show_bug.cgi?id=1169665
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update antiword’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

AutorTomislav Protega
Cert idNCERT-REF-2014-12-0034-ADV
CveCVE-2014-8123
ID izvornikaFEDORA-2014-16257 FEDORA-2014-16241
Proizvodantiword
Izvorhttp://www.redhat.com
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa phpmyadmin

Otkriveni su sigurnosni nedostaci u programskom paketu phpmyadmin. Otkriveni nedostaci potencijalnim napadačima omogućuju izvođenje DoS napada korištenjem dugačkih lozinki i...

Close