Re: [tdf-discuss] Re: security related information, CVE-2019-9848, CVE-2019-9849

2019-08-10 Thread Caolán McNamara
On Fri, 2019-08-09 at 21:38 -0700, Derek Currie wrote: > A further patch was supposed to be applied in version > 6.3.4 this week. > And yet there is no record in the release notes of that patch. > Instead, there is an incorrect listing that CVE-2019-9848 was patched > in v6.2.5.2, which has been

Re: [tdf-discuss] Re: security related information, CVE-2019-9848, CVE-2019-9849

2019-08-10 Thread Charles-H. Schulz
Hello Derek, Le 10 août 2019 06:38:34 GMT+02:00, Derek Currie a écrit : >I've been following this situation closely and advising users about the >workaround for *CVE-2019-9848*. > >*Problem:* The Document Foundation has stated that the patch for >CVE-2019-9848 was not entirely effective. I can

[tdf-discuss] Re: security related information, CVE-2019-9848, CVE-2019-9849

2019-08-09 Thread Derek Currie
I've been following this situation closely and advising users about the workaround for *CVE-2019-9848*. *Problem:* The Document Foundation has stated that the patch for CVE-2019-9848 was not entirely effective. I can provide documentation. A further patch was supposed to be applied in version