bug#30414: Libreoffice CVE-2018-6871 [remote read of any local files]

2018-02-12 Thread Leo Famulari
On Sun, Feb 11, 2018 at 03:34:42PM +, Marius Bakke wrote: > Never mind, it was actually completed by the time I packed up. > I pushed it (and fixed the merge conflict in xml.scm, sorry about that!). Awesome, thanks! signature.asc Description: PGP signature

bug#30414: Libreoffice CVE-2018-6871 [remote read of any local files]

2018-02-11 Thread Leo Famulari
On Sun, Feb 11, 2018 at 03:08:59PM +, Marius Bakke wrote: > I've attached a revised patch that adds libltdl, and removes the > automake inputs. However, I have to leave now, so could you please > verify that it works and push? I can provide moral support on #guix if > nothing else :-) Can so

bug#30414: Libreoffice CVE-2018-6871 [remote read of any local files]

2018-02-11 Thread Marius Bakke
On Sun, Feb 11, 2018, at 3:08 PM, Marius Bakke wrote: > Leo Famulari writes: > > >> From a28e82e1e3d480d5edf374cea062536d4c8d6d82 Mon Sep 17 00:00:00 2001 > >> From: Marius Bakke > >> Date: Sun, 11 Feb 2018 11:46:27 +0100 > >> Subject: [PATCH] gnu: libreoffice: Update to 5.4.5.1 [CVE-2018-6871].

bug#30414: Libreoffice CVE-2018-6871 [remote read of any local files]

2018-02-11 Thread Marius Bakke
Leo Famulari writes: >> From a28e82e1e3d480d5edf374cea062536d4c8d6d82 Mon Sep 17 00:00:00 2001 >> From: Marius Bakke >> Date: Sun, 11 Feb 2018 11:46:27 +0100 >> Subject: [PATCH] gnu: libreoffice: Update to 5.4.5.1 [CVE-2018-6871]. >> >> * gnu/packages/check.scm (cppunit-1.14): New public variab

bug#30414: Libreoffice CVE-2018-6871 [remote read of any local files]

2018-02-11 Thread Leo Famulari
On Sun, Feb 11, 2018 at 02:29:02PM +, Marius Bakke wrote: > I gave this a go, and there were (of course) a lot more changes > necessary to make this newer libreoffice build. In particular, it now > works with an external xmlsec (albeit NSS only), and it wants to build > PDFium(!) in the same f

bug#30414: Libreoffice CVE-2018-6871 [remote read of any local files]

2018-02-11 Thread Marius Bakke
[the café I'm at is blocking outgoing email, so resending through a browser] On Sun, Feb 11, 2018, at 1:27 AM, Marius Bakke wrote: > > > On February 10, 2018 10:49:52 PM GMT+01:00, Leo Famulari > wrote: > >I'm trying to update LibreOffice to 5.4.5.1. > > > >This version of LibreOffice requires

bug#30414: Libreoffice CVE-2018-6871 [remote read of any local files]

2018-02-10 Thread Leo Famulari
On Sun, Feb 11, 2018 at 02:27:44AM +0100, Marius Bakke wrote: > I was digging through the GitHub mirror, but haven't been able to find the > commit(s) in question: I haven't found them either. signature.asc Description: PGP signature

bug#30414: Libreoffice CVE-2018-6871 [remote read of any local files]

2018-02-10 Thread Marius Bakke
On February 10, 2018 10:49:52 PM GMT+01:00, Leo Famulari wrote: >I'm trying to update LibreOffice to 5.4.5.1. > >This version of LibreOffice requires cppunit to be updated to 1.14.0. > >However, this new version of cppunit requires C++11. > >This is not the default C++ standard in GCC 5, so thi

bug#30414: Libreoffice CVE-2018-6871 [remote read of any local files]

2018-02-10 Thread Leo Famulari
I'm trying to update LibreOffice to 5.4.5.1. This version of LibreOffice requires cppunit to be updated to 1.14.0. However, this new version of cppunit requires C++11. This is not the default C++ standard in GCC 5, so this update requires sprinkling "CXXFLAGS=-std=c++11" across several packages,

bug#30414: Libreoffice CVE-2018-6871 [remote read of any local files]

2018-02-10 Thread Leo Famulari
We need to fix CVE-2018-6871 in our LibreOffice package. This bug allows remote attackers to read any file accessible from LibreOffice by supplying a crafted file to open in LibreOffice. Apparently the bug is fixed in LibreOffice 5.4.5 or 6.0.1. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-