Re: [Libreoffice-qa] ESC meeting agenda: 2023-09-28 16:00 CEST

2023-09-29 Thread Eyal Rozenberg
The minutes item about the UI/UX aspect of dealing with security vulnerabilities is something that, in the last design meeting, John and myself specifically asked to be brought up at the ESC - assuming it would be part of a larger discussion of this matter. I want to thank Heiko for bringing

Re: [Libreoffice-qa] ESC meeting agenda: 2023-09-28 16:00 CEST

2023-09-29 Thread Xisco Fauli
Hello, This particular issue only affects users using LibreOffice 7.4, LibreOffice 7.5 and LibreOffice 7.6 since the Webp support was added in LibreOffice 7.4. See https://wiki.documentfoundation.org/ReleaseNotes/7.4 For those users still using LibreOffice 7.4, the official support of this

Re: [Libreoffice-qa] ESC meeting agenda: 2023-09-28 16:00 CEST

2023-09-28 Thread Eyal Rozenberg
But Sophie, from the dev point of view, the problem is actually not solved - until LO has a mechanism for pushing intrusive notifications of required critical updates (with an opt-out for people who don't want that). Some might disagree with this position, but it is certainly a matter for

Re: [Libreoffice-qa] ESC meeting agenda: 2023-09-28 16:00 CEST

2023-09-28 Thread sophi
Hi Eyal, John, Just to give some information on this peculiar episode. The CVE happened just before the conference where most of the team was traveling, not easy to do a respin in those conditions. What Miklos meant is that in the *dev* point of view it was solved, a fix has been provided

Re: [Libreoffice-qa] ESC meeting agenda: 2023-09-28 16:00 CEST

2023-09-28 Thread Eyal Rozenberg
I second John's sentiment. For the vast majority of LibreOffice users, this security problem is _not_ fixed. And that is because they run versions of LibreOffice with the vulnerability but without the fix; and have not been made aware of the vulnerability and the release-with-a-fix. I would

Re: [Libreoffice-qa] ESC meeting agenda: 2023-09-28 16:00 CEST

2023-09-28 Thread Miklos Vajna
Hi Eyal, On Wed, Sep 27, 2023 at 08:31:04PM +0300, Eyal Rozenberg wrote: > I would like to ask you to discuss the situation with the recent CVE: > https://bugs.documentfoundation.org/show_bug.cgi?id=157231 It was already discussed 2 weeks ago. If you have specific questions, please ask on the

Re: [Libreoffice-qa] ESC meeting agenda: 2023-09-28 16:00 CEST

2023-09-27 Thread Regina Henschel
Hi Eyal, Eyal Rozenberg schrieb am 27.09.2023 um 19:31: Hello ESC, I would like to ask you to discuss the situation with the recent CVE: https://bugs.documentfoundation.org/show_bug.cgi?id=157231 I'm not the ESC, but please notice

Re: [Libreoffice-qa] ESC meeting agenda: 2023-09-28 16:00 CEST

2023-09-27 Thread Eyal Rozenberg
Hello ESC, I would like to ask you to discuss the situation with the recent CVE: https://bugs.documentfoundation.org/show_bug.cgi?id=157231 which potentially affects LibreOffice: https://bugs.documentfoundation.org/show_bug.cgi?id=157231 Specifically: 1. Please asses the potential effect on

[Libreoffice-qa] ESC meeting agenda: 2023-09-28 16:00 CEST

2023-09-27 Thread Miklos Vajna
Hi, The prototype agenda is below. Extra items are appreciated either in this document or as a reply to this mail: https://pad.documentfoundation.org/p/esc You can join using Jitsi here: https://jitsi.documentfoundation.org/esc Regards, Miklos --- * Present: + * Completed Action