LibreOffice users ought to update their software: a security hole has been discovered in the code used to import Microsoft Word documents into the open-source productivity suite. The latest version of the software contains a fix for the problem. A memory corruption-related vulnerability in the import code creates a possible …
Quick off the mark …
It looks as if 3.4.3 has been available since 31st August, why a story about this today? Or did I miss something?
That version was released a month ago
LibreOffice 3.4.3 Final came out 2011-08-31
If they fixed it in 3.4.3 which was released in August - why have they not notified us before?
They were knowingly (and still?) recommending corporate/stable to use an insecure version 3.3.4
Shame that in order to update you have to download the full 150MB thing and re-install.
Hopefully LibreOffice will one day implement an auto-update system which doesn't require manually downloading and re-installing. And instead just updates the changed components.
I have a feeling, that I read somewhere, that someone owns the patents to that sort of system, probably Apple or Microsoft ...
So Firefox, Thunderbird, Opera, Chrome, Azureues/Vuze, jEdit etc. And Adobe Creative Suite I believe downloads and integrate updates without re-installing the whole lot. And not forgetting the many Linux distros that download and update changed components via a package manager.
All in violation of a patent? Wowzer!
Doesn't sound hugely serious
Unless you worked for a company which was known to use LibreOffice, the chances of receiving a tainted .doc file with the express intent you open it up in another produce seems pretty low.
It would be nice if LibreOffice did implement a patch based update system. Such things exist. There should be no reason to have to have to download a 150Mb product and go through a full reinstall just to fix a handful of files.
You don't update Windows then?
Excuse me, you think 150 MB is an unreasonably large update patch?
Windows has security advisory -notices- that large.
Well, not quite. But if you're using LibreOffice, then it's quite likely that you don't have to keep Microsoft Office up to date on the same PC. That is a major saving.
Is big one. Unless I'm doing a massive update I don't see any thing that big. My last office up date was 23 megs.
Mine appears to come with .NET... that isn't helping. (Well, not in this respect.)
Vulnerabilities, huh? I've seen they've taken Microsoft Word compatibility one step too far.
- NASA boffin: RIDDLE of odd BULGE FOUND on MOON is SOLVED
- Pic Mars rover 2020: Oxygen generation and 6 more amazing experiments
- Microsoft's Euro cloud darkens: US FEDS can dig into foreign servers
- Plug and PREY: Hackers reprogram USB drives to silently infect PCs
- Boffins spot weirder quantum capers as neutrons take the high road, spin takes the low