[tdf-discuss] security related information, CVE-2020-12801

2020-05-18 Thread Caolán McNamara
CVE-2020-12801 Crash-recovered MSOffice encrypted documents defaulted
to not to using encryption on next save

If LibreOffice has an encrypted document open and crashes, that
document is auto-saved encrypted. On restart, LibreOffice offers to
restore the document and prompts for the password to decrypt it. If the
recovery is successful, and if the file format of the recovered
document was not LibreOffice's default ODF file format, then affected
versions of LibreOffice default that subsequent saves of the document
are unencrypted.
 
This may lead to a user accidentally saving a MSOffice file format
document unencrypted while believing it to be encrypted.

This is fixed, in the 6-3 series with 6.3.6 and in the 6-4 series with
6.4.3


-- 
To unsubscribe e-mail to: discuss+unsubscr...@documentfoundation.org
Problems? https://www.libreoffice.org/get-help/mailing-lists/how-to-unsubscribe/
Posting guidelines + more: https://wiki.documentfoundation.org/Netiquette
List archive: https://listarchives.documentfoundation.org/www/discuss/
Privacy Policy: https://www.documentfoundation.org/privacy


[board-discuss] Public agenda for TDF board meeting on Friday, May 22nd at 1300 Berlin time (UTC+2)

2020-05-18 Thread Florian Effenberger

Dear community,

find below the public agenda for our

-> TDF board meeting with a public part, and if needed followed by a 
private part (- no topics in the private part so far -)

-> on Friday, May 22nd at 1300 Berlin time

For time zone conversion, see e.g.
https://www.timeanddate.com/worldclock/converted.html?iso=20200522T13=37=136=241=589

-> at https://jitsi.documentfoundation.org/TDFBoard

as we gain good experience last time after improvements of the TDF 
instance from the team, if possible use Chrome browser and do not use 
video and until not speaking up please mute.


-> AGENDA:

Public Part

1. Q: Answering Questions from the community (All, max. 10 minutes)

   Rationale: Provide an opportunity for the community to ask questions 
to the new board and about TDF.


2. Discuss: Ecosystem & Sustainability (Michael, All 15min)

   Rationale: Discussion, relevance and dependencies for TDF

3. Discuss: Quick check of fitting prerequisites and procedure of the 
vote for the next agenda item (Lothar, Board members, All 5 minutes)


   Rationale: Clarifying about voting of the next agenda item

4. Voting on proposal of Paolo:  (Paolo, Board members 15 minutes)

   Voting proposal via Mail from Paolo Vecchi at 16.05., 13.15 UTC+2: "...

   Enable the infrastructure team to deliver the following packages 
with TDF and LibreOffice branding:

- docker images
- ownCloud connector (from which we have already got confirmation 
of acceptance) for LOOL
- once that is in place I will ask NextCloud for the opportunity to 
do the same

- Univention marketplace packages for LOOL
- all packages and connectors will be maintained and updated on a 
monthly basis unless urgent patches/bug fixes are required sooner
- the latest stable version of LOOL code will be used to build the 
images
- the infrastructure oversight team will ensure that all issues 
that may impede the execution of this plan are identified and solved 
promptly
- the infrastructure oversight team should evaluate, and report 
back to the BoD, if TDF should use its own Gerrit server for LOOL or 
Collabora's see ticket

https://bugs.documentfoundation.org/show_bug.cgi?id=132349
- LibreOffice branded documentation/help files should be created to 
make it as easy as possible to install docker images/Univention packages
- TDF's LOOL packages will be free and supported only by the 
community. No paid/support options will be made available by TDF
- In the download page it will be made clear that if LOOL is used 
in enterprise environment support options are available through the 
members of TDF's ecosystem
  At a later stage eventual limitations in terms of concurrent 
users/documents will be discussed.

  ..."

  Rationale: explanation of voting item(s), getting a valid voting 
result on Paolos proposal as described above


5. Discuss: Status of redmine tickets of the board (Thorsten, All 10min)

   Rationale: Clarifying which tickets/list, what todos, who is caring, 
until when


 Private Part

 - No topic in private so far -

Florian

--
Florian Effenberger, Executive Director (Geschäftsführer)
Tel: +49 30 5557992-50 | Mail: flo...@documentfoundation.org
The Document Foundation, Kurfürstendamm 188, 10707 Berlin, DE
Gemeinnützige rechtsfähige Stiftung des bürgerlichen Rechts
Legal details: https://www.documentfoundation.org/imprint

--
To unsubscribe e-mail to: board-discuss+unsubscr...@documentfoundation.org
Problems? https://www.libreoffice.org/get-help/mailing-lists/how-to-unsubscribe/
Posting guidelines + more: https://wiki.documentfoundation.org/Netiquette
List archive: https://listarchives.documentfoundation.org/www/board-discuss/
Privacy Policy: https://www.documentfoundation.org/privacy