<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://blog.gmane.org/gmane.comp.openoffice.announce.security">
    <title>gmane.comp.openoffice.announce.security</title>
    <link>http://blog.gmane.org/gmane.comp.openoffice.announce.security</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/17"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/16"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/15"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/14"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/13"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/12"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/11"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/10"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/9"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/8"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/7"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/6"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/5"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/4"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/3"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/2"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/1"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/17">
    <title>CVE-2010-3689: Insecure LD_LIBRARY_PATH usage in OpenOffice.org shell scripts</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/17</link>
    <description>&lt;pre&gt;CVE-2010-3689

Insecure LD_LIBRARY_PATH usage in OpenOffice.org shell scripts

    * Synopsis: The OpenOffice.org start script and other shell scripts
      expand the LD_LIBRARY_PATH in a insecure way
    * State: Resolved

1. Impact

The OpenOffice.org start script and other shell scripts expand the
LD_LIBRARY_PATH in a way that the current directory might be searched
for libraries before /lib and /usr/lib, which can have security
implications.

2. Affected releases

    * All versions of OpenOffice.org 3 prior to version 3.3

    Note: OpenOffice.org 2 is not impacted by this issue.
          Earlier versions of OpenOffice.org are no longer supported
          and will not be evaluated regarding this issue.

3. Symptoms

There are no predictable symptoms that would indicate this issue has
occurred.

4. Relief/Workaround

To workaround the described issue, make sure that LD_LIBRARY_PATH is not
empty before running soffice or other OpenOffice.org shell scripts.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.3

6. Comments

OpenOffice.org acknowledges with thanks, Dmitri Gribenko.

Reference: http://www.openoffice.org/security/bulletin.html
&lt;/pre&gt;</description>
    <dc:creator>Malte Timmermann</dc:creator>
    <dc:date>2011-01-28T11:10:58</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/16">
    <title>CVE-2010-3451 / CVE-2010-3452: Security Vulnerability in OpenOffice.org related to RTF document processing</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/16</link>
    <description>&lt;pre&gt;CVE-2010-3451 CVE-2010-3452

Security Vulnerability in OpenOffice.org related to RTF document processing

    * Synopsis: A security vulnerability in OpenOffice.org, related to
      RTF document processing, may lead to arbitrary code execution.
    * State: Resolved

1. Impact

A security vulnerability in OpenOffice.org, related to RTF document
processing, may allow a remote unprivileged user to execute arbitrary
code on the system with the privileges of a local user running
OpenOffice.org, if the local user opens a crafted RTF document provided
by the remote user.

2. Affected releases

    * All versions of OpenOffice.org 3 prior to version 3.3
    * All versions of OpenOffice.org 2

    Note: Earlier versions of OpenOffice.org are no longer supported
          and will not be evaluated regarding this issue.

3. Symptoms

There are no predictable symptoms that would indicate this issue has
occurred.

4. Relief/Workaround

To workaround the described issue, do not load documents from untrusted
sources.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.3

6. Comments

OpenOffice.org acknowledges with thanks, Dan Rosenberg of Virtual
Security Research.

Reference: http://www.openoffice.org/security/bulletin.html
&lt;/pre&gt;</description>
    <dc:creator>Malte Timmermann</dc:creator>
    <dc:date>2011-01-28T11:10:48</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/15">
    <title>CVE-2010-3453 / CVE-2010-3454: Security Vulnerability in OpenOffice.org related to Word document processing</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/15</link>
    <description>&lt;pre&gt;CVE-2010-3453 CVE-2010-3454

Security Vulnerability in OpenOffice.org related to Word document processing

    * Synopsis: A security vulnerability in OpenOffice.org, related to
      Word document processing, may lead to arbitrary code execution.
    * State: Resolved

1. Impact

A security vulnerability in OpenOffice.org, related to Word document
processing, may allow a remote unprivileged user to execute arbitrary
code on the system with the privileges of a local user running
OpenOffice.org, if the local user opens a crafted Word document provided
by the remote user.

2. Affected releases

    * All versions of OpenOffice.org 3 prior to version 3.3
    * All versions of OpenOffice.org 2

    Note: Earlier versions of OpenOffice.org are no longer supported
          and will not be evaluated regarding this issue.

3. Symptoms

There are no predictable symptoms that would indicate this issue has
occurred.

4. Relief/Workaround

To workaround the described issue, do not load documents from untrusted
sources.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.3

6. Comments

OpenOffice.org acknowledges with thanks, Dan Rosenberg of Virtual
Security Research.

Reference: http://www.openoffice.org/security/bulletin.html
&lt;/pre&gt;</description>
    <dc:creator>Malte Timmermann</dc:creator>
    <dc:date>2011-01-28T11:10:53</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/14">
    <title>CVE-2010-4008 / CVE-2010-4494: Possible Security Vulnerability in OpenOffice.org resulting from 3rd party library LIBXML2</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/14</link>
    <description>&lt;pre&gt;CVE-2010-4008 CVE-2010-4494

Possible Security Vulnerability in OpenOffice.org resulting from 3rd
party library LIBXML2

    * Synopsis: OpenOffice.org comes with a vulnerable version of 3rd
      party library LIBXML2
    * State: Resolved

1. Impact

OpenOffice.org comes with a vulnerable version of 3rd party library
LIBXML2, but it's unclear whether or not OpenOffice.org actually is
impacted by these issues.

2. Affected releases

    * All versions of OpenOffice.org 3 prior to version 3.3
    * All versions of OpenOffice.org 2

    Note: Earlier versions of OpenOffice.org are no longer supported
          and will not be evaluated regarding this issue.

3. Symptoms

There are no predictable symptoms that would indicate this issue has
occurred.

4. Relief/Workaround

None.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.3

Reference: http://www.openoffice.org/security/bulletin.html
&lt;/pre&gt;</description>
    <dc:creator>Malte Timmermann</dc:creator>
    <dc:date>2011-01-28T11:11:08</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/13">
    <title>CVE-2010-3702 / CVE-2010-3704: Security Vulnerability in OpenOffice.org's PDF Import extension resulting from 3rd party library XPDF</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/13</link>
    <description>&lt;pre&gt;CVE-2010-3702 CVE-2010-3704

Security Vulnerability in OpenOffice.org's PDF Import extension
resulting from 3rd party library XPDF

    * Synopsis: A security vulnerability in the 3rd party library XPDF,
      related to PDF document processing, may lead to arbitrary code
      execution.
    * State: Resolved

1. Impact

A security vulnerability in the 3rd party library XPDF (only used in the
PDF import extension), related to PDF document processing, may allow a
remote unprivileged user to execute arbitrary code on the system with
the privileges of a local user running OpenOffice.org, if the local user
opens a crafted PDF document provided by the remote user.

2. Affected releases

    * All versions of OpenOffice.org's PDF Import extension prior to
      version 1.0.4

3. Symptoms

There are no predictable symptoms that would indicate this issue has
occurred.

4. Relief/Workaround

To workaround the described issue, do not load documents from untrusted
sources.

5. Resolution

This issue is addressed in the following release: PDF Import Extension 1.0.4

Reference: http://www.openoffice.org/security/bulletin.html
&lt;/pre&gt;</description>
    <dc:creator>Malte Timmermann</dc:creator>
    <dc:date>2011-01-28T11:11:03</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/12">
    <title>CVE-2010-2935 / CVE-2010-2936: Security Vulnerability in OpenOffice.org related to PowerPoint document processing</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/12</link>
    <description>&lt;pre&gt;CVE-2010-2935 CVE-2010-2936

Security Vulnerability in OpenOffice.org related to PowerPoint document
processing

    * Synopsis: A security vulnerability in OpenOffice.org, related to
      PowerPoint document processing, may lead to arbitrary code
      execution.
    * State: Resolved

1. Impact

A security vulnerability in OpenOffice.org, related to PowerPoint
document processing, may allow a remote unprivileged user to execute
arbitrary code on the system with the privileges of a local user running
OpenOffice.org, if the local user opens a crafted PowerPoint document
provided by the remote user.

2. Affected releases

    * All versions of OpenOffice.org 3 prior to version 3.3
    * All versions of OpenOffice.org 2

    Note: Earlier versions of OpenOffice.org are no longer supported
          and will not be evaluated regarding this issue.

3. Symptoms

There are no predictable symptoms that would indicate this issue has
occurred.

4. Relief/Workaround

To workaround the described issue, do not load documents from untrusted
sources.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.3


Reference: http://www.openoffice.org/security/bulletin.html
&lt;/pre&gt;</description>
    <dc:creator>Malte Timmermann</dc:creator>
    <dc:date>2011-01-28T11:10:31</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/11">
    <title>CVE-2010-4643: Security Vulnerability in OpenOffice.org related to TGA file processing</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/11</link>
    <description>&lt;pre&gt;CVE-2010-4643

Security Vulnerability in OpenOffice.org related to TGA file processing

    * Synopsis: A security vulnerability in OpenOffice.org, related to
      TGA file processing, may lead to arbitrary code execution.
    * State: Resolved

1. Impact

A security vulnerability in OpenOffice.org, related to TGA file
processing, may allow a remote unprivileged user to execute arbitrary
code on the system with the privileges of a local user running
OpenOffice.org, if the local user opens a crafted TGA file provided by
the remote user.
Note: TGA files could be embedded in many different document types,
including all kind of ODF and MS Office documents.

2. Affected releases

    * All versions of OpenOffice.org 3 prior to version 3.3
    * All versions of OpenOffice.org 2

    Note: Earlier versions of OpenOffice.org are no longer supported
          and will not be evaluated regarding this issue.

3. Symptoms

There are no predictable symptoms that would indicate this issue has
occurred.

4. Relief/Workaround

To workaround the described issue, do not load documents from untrusted
sources.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.3

6. Comments

OpenOffice.org acknowledges with thanks, babi working with Beyond
Security's SecuriTeam Secure Disclosure program.

Reference: http://www.openoffice.org/security/bulletin.html
&lt;/pre&gt;</description>
    <dc:creator>Malte Timmermann</dc:creator>
    <dc:date>2011-01-28T11:11:18</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/10">
    <title>CVE-2010-4253: Security Vulnerability in OpenOffice.org related to PNG file processing</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/10</link>
    <description>&lt;pre&gt;CVE-2010-4253

Security Vulnerability in OpenOffice.org related to PNG file processing

    * Synopsis: A security vulnerability in OpenOffice.org, related to
      PNG file processing, may lead to arbitrary code execution.
    * State: Resolved

1. Impact

A security vulnerability in OpenOffice.org, related to PNG file
processing, may allow a remote unprivileged user to execute arbitrary
code on the system with the privileges of a local user running
OpenOffice.org, if the local user opens a crafted PNG file provided by
the remote user.
Note: PNG files could be embedded in many different document types,
including all kind of ODF and MS Office documents.

2. Affected releases

    * All versions of OpenOffice.org 3 prior to version 3.3
    * All versions of OpenOffice.org 2

    Note: Earlier versions of OpenOffice.org are no longer supported
          and will not be evaluated regarding this issue.

3. Symptoms

There are no predictable symptoms that would indicate this issue has
occurred.

4. Relief/Workaround

To workaround the described issue, do not load documents from untrusted
sources.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.3

6. Comments

OpenOffice.org acknowledges with thanks, Marc Schoenefeld from Red Hat
Security Response Team.

Reference: http://www.openoffice.org/security/bulletin.html
&lt;/pre&gt;</description>
    <dc:creator>Malte Timmermann</dc:creator>
    <dc:date>2011-01-28T11:11:13</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/9">
    <title>CVE-2010-3450: Security Vulnerability in OpenOffice.org related to Extensions and filter package files</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/9</link>
    <description>&lt;pre&gt;CVE-2010-3450

Security Vulnerability in OpenOffice.org related to Extensions and
filter package files

    * Synopsis: A directory traversal vulnerability in OpenOffice.org,
      related to zip/jar package extraction, may lead to overwriting
      files and even to arbitrary code execution.
    * State: Resolved

1. Impact

A directory traversal vulnerability in OpenOffice.org, related to
zip/jar package extraction, may lead to overwriting files when relative
file locations point to locations outside the root of the destination
folder. This way important files could be overwritten, including
executables.

2. Affected releases

    * All versions of OpenOffice.org 3 prior to version 3.3
    * All versions of OpenOffice.org 2

    Note: Earlier versions of OpenOffice.org are no longer supported
          and will not be evaluated regarding this issue.

3. Symptoms

There are no predictable symptoms that would indicate this issue has
occurred.

4. Relief/Workaround

To workaround the described issue, do not load extensions or filter
package files from untrusted sources.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.3

6. Comments

OpenOffice.org acknowledges with thanks, Marc Schoenefeld from Red Hat
Security Response Team.

Reference: http://www.openoffice.org/security/bulletin.html
&lt;/pre&gt;</description>
    <dc:creator>Malte Timmermann</dc:creator>
    <dc:date>2011-01-28T11:10:42</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/8">
    <title>[security-alerts] CVE-2010-0395: Security vulnerability in OpenOffice.org related to python scripting</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/8</link>
    <description>&lt;pre&gt;Synopsis

CVE-2010-0395: Security vulnerability in OpenOffice.org related to 
python scripting


1. Impact

A security vulnerability in OpenOffice.org related to python scripting 
might lead to unexpected code execution when using the built-in 
scripting IDE for exploring the python code.

2. Affected releases

All versions of OpenOffice.org 3 prior to version 3.2.1
All versions of OpenOffice.org 2

Note: Earlier versions of OpenOffice.org are no longer supported and 
will not be evaluated regarding this issue.

3. Symptoms

There are no predictable symptoms that would indicate this issue has 
occurred.

4. Relief/Workaround

As a workaround, do not inspect python code from non-trustworthy 
documents with the built-in scripting IDE and its dialogs.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.2.1
&lt;/pre&gt;</description>
    <dc:creator>Florian Effenberger</dc:creator>
    <dc:date>2010-06-04T10:19:25</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/7">
    <title>[security-alerts] CVE-2009-3555: OpenOffice.org 2 and 3 may be affected by the TLS/SSL Renegotiation Issue in 3rd Party Libraries</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/7</link>
    <description>&lt;pre&gt;Synopsis

CVE-2009-3555: OpenOffice.org 2 and 3 may be affected by the TLS/SSL 
Renegotiation Issue in 3rd Party Libraries


1. Impact

OpenOffice.org 2 and 3 ship with 3rd party libraries affected by the 
TLS/SSL renegotiation issue documented in CVE-2009-3555.

2. Affected releases

All versions of OpenOffice.org 3 prior to version 3.2.1
All versions of OpenOffice.org 2

Note: OpenOffice.org 1.1 is not impacted by this issue.

3. Symptoms

There are no predictable symptoms that would indicate this issue has 
occurred.

4. Relief/Workaround

None.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.2.1
&lt;/pre&gt;</description>
    <dc:creator>Florian Effenberger</dc:creator>
    <dc:date>2010-06-04T08:51:57</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/6">
    <title>[security-alerts] CVE-2009-3301, CVE-2009-3302: Security Vulnerability in OpenOffice.org related to MS-Word document processing</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/6</link>
    <description>&lt;pre&gt;CVE-2009-3301, CVE-2009-3302: Security Vulnerability in OpenOffice.org 
related to MS-Word document processing

* Synopsis: A security vulnerability in OpenOffice.org, related to 
MS-Word document processing, may lead to arbitrary code execution.

* State: Resolved

1. Impact

A security vulnerability in OpenOffice.org, related to Word document 
processing, may allow a remote unprivileged user to execute arbitrary 
code on the system with the privileges of a local user running 
OpenOffice.org, if the local user opens a crafted Word document provided 
by the remote user.

2. Affected releases

All versions of OpenOffice.org prior to version 3.2

3. Symptoms

There are no predictable symptoms that would indicate this issue has 
occurred.

4. Relief/Workaround

To workaround the described issue, do not load documents from untrusted 
sources.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.2

6. Comments

OpenOffice.org acknowledges with thanks, Nicolas Joly of VUPEN 
Vulnerability Research Team.
&lt;/pre&gt;</description>
    <dc:creator>Florian Effenberger</dc:creator>
    <dc:date>2010-02-12T11:04:00</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/5">
    <title>[security-alerts] CVE-2009-2950: Security Vulnerability in OpenOffice.org related to GIF file processing</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/5</link>
    <description>&lt;pre&gt;CVE-2009-2950: Security Vulnerability in OpenOffice.org related to GIF 
file processing

* Synopsis: Security Vulnerability in OpenOffice.org related to GIF 
file processing may lead to arbitrary code execution

* State: Resolved

1. Impact

A security vulnerability in OpenOffice.org, related to GIF file 
processing, may allow a remote unprivileged user to execute arbitrary 
code on the system with the privileges of a local user running 
OpenOffice.org, if the local user opens a crafted GIF file provided by 
the remote user. GIF files can also be embedded in different kind of 
documents, including documents in the OpenDocument Format (ODF), the 
default format used by OpenOffice.org.

2. Affected releases

All versions of OpenOffice.org prior to version 3.2

3. Symptoms

There are no predictable symptoms that would indicate this issue has 
occurred.

4. Relief/Workaround

To workaround the described issue, do not load documents from untrusted 
sources.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.2

6. Comments

OpenOffice.org acknowledges with thanks, Frank Reißner and Sebastian 
Apelt from siberas.
&lt;/pre&gt;</description>
    <dc:creator>Florian Effenberger</dc:creator>
    <dc:date>2010-02-12T11:03:27</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/4">
    <title>[security-alerts] CVE-2009-2949: Security Vulnerability in OpenOffice.org related to XPM file processing</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/4</link>
    <description>&lt;pre&gt;CVE-2009-2949: Security Vulnerability in OpenOffice.org related to XPM 
file processing

* Synopsis: Security Vulnerability in OpenOffice.org related to XPM 
file processing may lead to arbitrary code execution

* State: Resolved

1. Impact

A security vulnerability in OpenOffice.org, related to XPM file 
processing, may allow a remote unprivileged user to execute arbitrary 
code on the system with the privileges of a local user running 
OpenOffice.org, if the local user opens a crafted XPM file provided by 
the remote user. XPM files can also be embedded in different kind of 
documents, including documents in the OpenDocument Format (ODF), the 
default format used by OpenOffice.org.

2. Affected releases

All versions of OpenOffice.org prior to version 3.2

3. Symptoms

There are no predictable symptoms that would indicate this issue has 
occurred.

4. Relief/Workaround

To workaround the described issue, do not load documents from untrusted 
sources.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.2

6. Comments

OpenOffice.org acknowledges with thanks Sebastian Apelt from siberas.
&lt;/pre&gt;</description>
    <dc:creator>Florian Effenberger</dc:creator>
    <dc:date>2010-02-12T11:03:05</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/3">
    <title>[security-alerts] CVE-2009-2493: OpenOffice.org 3 for Windows bundles a vulnerable version of MSVC Runtime</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/3</link>
    <description>&lt;pre&gt;CVE-2009-2493: OpenOffice.org 3 for Windows bundles a vulnerable version 
of MSVC Runtime

* Synopsis: OpenOffice.org 3 for Windows includes a vulnerable version 
of the MSVC Runtime, see CVE-2009-2493 for details.

* State: Resolved

1. Impact

OpenOffice.org 3 for Windows ships with a vulnerable version of the MSVC 
Runtime, CVE-2009-2493 for details. OpenOffice.org is not affected by 
the security issue, but centrally installs the vulnerable MSVC Runtime 
if it didn't exist on the system before. The vulnerable version should 
be updated automatically by the monthly Windows updates, but newer 
versions of OpenOffice.org also come with the updated MSVC Runtime.

2. Affected releases

* All versions of OpenOffice.org 3 for Windows prior to version 3.2

Note: OpenOffice.org 2 and OpenOffice.org 1.1 are not impacted by this 
issue.

3. Symptoms

There are no predictable symptoms that would indicate this issue has 
occurred.

4. Relief/Workaround

None.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.2
&lt;/pre&gt;</description>
    <dc:creator>Florian Effenberger</dc:creator>
    <dc:date>2010-02-12T11:02:35</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/2">
    <title>[security-alerts] CVE-2009-0217: Security Vulnerability in OpenOffice.org resulting from 3rd party library</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/2</link>
    <description>&lt;pre&gt;CVE-2009-0217: Security Vulnerability in OpenOffice.org resulting from 
3rd party library

* Synopsis: OpenOffice.org 2 and 3 might be affected by XML signature 
HMAC truncation authentication bypass issue in 3rd party library libxmlsec

* State: Resolved

1. Impact

OpenOffice.org 2 and 3 ship with 3rd party libraries affected by the XML 
signature HMAC truncation authentication bypass issue documented in 
CVE-2009-0217.

2. Affected releases

* All versions of OpenOffice.org 3 prior to version 3.2

* All versions of OpenOffice.org 2

3. Symptoms

There are no predictable symptoms that would indicate this issue has 
occurred.

4. Relief/Workaround

None.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.2
&lt;/pre&gt;</description>
    <dc:creator>Florian Effenberger</dc:creator>
    <dc:date>2010-02-12T11:02:08</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.openoffice.announce.security/1">
    <title>[security-alerts] CVE-2006-4339: Security Vulnerability in OpenOffice.org resulting from 3rd party libraries</title>
    <link>http://permalink.gmane.org/gmane.comp.openoffice.announce.security/1</link>
    <description>&lt;pre&gt;CVE-2006-4339: Security Vulnerability in OpenOffice.org resulting from 
3rd party libraries

* Synopsis: OpenOffice.org 2 and 3 might fail to handle signatures 
properly due to an issue in 3rd party library libxml2.

* State: Resolved

1. Impact

OpenOffice.org 2 and 3 might fail to handle signatures properly due to 
the use of a 3rd party library known for having the issue described in 
CVE-2006-4339.

2. Affected releases

* All versions of OpenOffice.org 3 prior to version 3.2

* All versions of OpenOffice.org 2

Note: OpenOffice.org 1.1 is not impacted by this issue.

3. Symptoms

There are no predictable symptoms that would indicate this issue has 
occurred.

4. Relief/Workaround

None.

5. Resolution

This issue is addressed in the following release: OpenOffice.org 3.2
&lt;/pre&gt;</description>
    <dc:creator>Florian Effenberger</dc:creator>
    <dc:date>2010-02-12T11:01:36</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.comp.openoffice.announce.security">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.comp.openoffice.announce.security</link>
  </textinput>
</rdf:RDF>
