Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-FU-2022:0039-1

Опубликовано: 10 янв. 2022
Источник: suse-cvrf

Описание

Feature update for zxing-cpp libreoffice

This feature update for zxing-cpp and libreoffice fixes the following issues:

Update LibreOffice from version 7.1.3.2 to 7.2.3.2 (jsc#SLE-18213):

  • Fix external URL connections issues when WebDav is built using libserf. (bsc#1187173, bsc#1186871)
  • Fix an issue with PPTX where one column becomes two within one text frame. (bsc#1182969)
  • Fix inteaction between multi-column shape text and automatic height. (bsc#1187982)
  • Fix interaction of transparent cell fill and transparent shadow. (bsc#1189813)
  • Fix lost bullet mode while typing and text is not visible.
  • Use external poppler version 21.01.0 (jsc#SLE-18213)
  • Use external CMIS version 0.5.2
  • Update external boost to version 1.75.0
  • Update external pdfium to version 4500
  • Update external skia to version 'm90'
  • Do not use qrcodegen-devel but move to zxing-cpp (jsc#SLE-18213)
  • Keep upstream desktop file names (bsc#1183655)
  • Display math icon (bsc#1180479)
  • Source profile.d/alljava.sh from either /etc (if found) or /usr/etc.

Update libserf from version 1.3.7 to version 1.3.9 (jsc#SLE-18213):

  • serf is now Apache Software Foundation project
  • Reset state variables when resetting connection
  • Fix some usages of the openssl BIO api
  • Improve handling of bad data in the response state line
  • Support more overrides via SCons arguments
  • Adapt to OpenSSL 1.1.x api
  • CVE-2014-3566: Fix the handling of very large gzip-encoded HTTP responses and disables SSLv2 and SSLv3. (bsc#901968)
    • CRC calculation error for gzipped http reponses > 4GB.
    • SSPI CredHandle not freed when APR pool is destroyed.
    • Disable SSLv2 and SSLv3 as both are broken

Provide zxing-cpp 1.2.0 as new LibreOffice dependency (jsc#SLE-18213):

  • Do not build examples to avoid a cycle with QT5Multimedia
  • Use cmake3-full package instead of cmake on SUSE Linux Enterprise 12
  • Do not build examples on SUSE Linux Enterprise 12
  • Only build blackbox tests on openSUSE Tumbleweed
  • New BarcodeFormat
  • New ZXingQtCamReader demo app based on QtMultimedia and QtQuick
  • New QRCode reader, faster and better support for rotated symbols
  • Add Structured Append support for DataMatrix, Aztec and MaxiCode
  • Add DMRE support for DataMatrix
  • Switch to the reimplemented 1D detectors, about 5x faster
  • Faster and more capable isPure detection for all 2D codes
  • 20% faster ReedSolomon error correction.
  • ReedSolomon error detection code 2x speedup.
  • PDF417 is faster and supports flipped symbols
  • Reduced false positive rate for UPC/EAN barcodes and improved Add-On symbol handling
  • Fix country-code metadata decoding for UPC/EAN codes.
  • Proper ECI handling in all 2D barcodes
  • Add baselibs.conf
  • Many performance improvements for 1D readers
  • More meta-data exported when reading specific format
  • Improve DataMatrix encoder
  • Add interface to simplify basic usage
  • WASM API to support pixels array as input
  • 'LuminanceSource' based API is now deprecated but still compiles.
  • New BarcodeFormats flag type to specify the set of barcodes to look for.
  • New simplified and consistent Python API
  • Slightly improved QRCode detection for rotated symbols.

Список пакетов

SUSE Linux Enterprise Software Development Kit 12 SP5
libZXing1-1.2.0-8.3.3
libreoffice-sdk-7.2.3.2-48.11.4
libserf-1-1-1.3.9-9.5.3
libserf-devel-1.3.9-9.5.3
zxing-cpp-devel-1.2.0-8.3.3
SUSE Linux Enterprise Workstation Extension 12 SP5
libZXing1-1.2.0-8.3.3
libreoffice-7.2.3.2-48.11.4
libreoffice-base-7.2.3.2-48.11.4
libreoffice-base-drivers-postgresql-7.2.3.2-48.11.4
libreoffice-branding-upstream-7.2.3.2-48.11.4
libreoffice-calc-7.2.3.2-48.11.4
libreoffice-calc-extensions-7.2.3.2-48.11.4
libreoffice-draw-7.2.3.2-48.11.4
libreoffice-filters-optional-7.2.3.2-48.11.4
libreoffice-gnome-7.2.3.2-48.11.4
libreoffice-gtk3-7.2.3.2-48.11.4
libreoffice-icon-themes-7.2.3.2-48.11.4
libreoffice-impress-7.2.3.2-48.11.4
libreoffice-l10n-af-7.2.3.2-48.11.4
libreoffice-l10n-ar-7.2.3.2-48.11.4
libreoffice-l10n-bg-7.2.3.2-48.11.4
libreoffice-l10n-ca-7.2.3.2-48.11.4
libreoffice-l10n-cs-7.2.3.2-48.11.4
libreoffice-l10n-da-7.2.3.2-48.11.4
libreoffice-l10n-de-7.2.3.2-48.11.4
libreoffice-l10n-en-7.2.3.2-48.11.4
libreoffice-l10n-es-7.2.3.2-48.11.4
libreoffice-l10n-fi-7.2.3.2-48.11.4
libreoffice-l10n-fr-7.2.3.2-48.11.4
libreoffice-l10n-gu-7.2.3.2-48.11.4
libreoffice-l10n-hi-7.2.3.2-48.11.4
libreoffice-l10n-hr-7.2.3.2-48.11.4
libreoffice-l10n-hu-7.2.3.2-48.11.4
libreoffice-l10n-it-7.2.3.2-48.11.4
libreoffice-l10n-ja-7.2.3.2-48.11.4
libreoffice-l10n-ko-7.2.3.2-48.11.4
libreoffice-l10n-lt-7.2.3.2-48.11.4
libreoffice-l10n-nb-7.2.3.2-48.11.4
libreoffice-l10n-nl-7.2.3.2-48.11.4
libreoffice-l10n-nn-7.2.3.2-48.11.4
libreoffice-l10n-pl-7.2.3.2-48.11.4
libreoffice-l10n-pt_BR-7.2.3.2-48.11.4
libreoffice-l10n-pt_PT-7.2.3.2-48.11.4
libreoffice-l10n-ro-7.2.3.2-48.11.4
libreoffice-l10n-ru-7.2.3.2-48.11.4
libreoffice-l10n-sk-7.2.3.2-48.11.4
libreoffice-l10n-sv-7.2.3.2-48.11.4
libreoffice-l10n-uk-7.2.3.2-48.11.4
libreoffice-l10n-xh-7.2.3.2-48.11.4
libreoffice-l10n-zh_CN-7.2.3.2-48.11.4
libreoffice-l10n-zh_TW-7.2.3.2-48.11.4
libreoffice-l10n-zu-7.2.3.2-48.11.4
libreoffice-librelogo-7.2.3.2-48.11.4
libreoffice-mailmerge-7.2.3.2-48.11.4
libreoffice-math-7.2.3.2-48.11.4
libreoffice-officebean-7.2.3.2-48.11.4
libreoffice-pyuno-7.2.3.2-48.11.4
libreoffice-writer-7.2.3.2-48.11.4
libreoffice-writer-extensions-7.2.3.2-48.11.4
libserf-1-1-1.3.9-9.5.3

Описание

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.


Затронутые продукты
SUSE Linux Enterprise Software Development Kit 12 SP5:libZXing1-1.2.0-8.3.3
SUSE Linux Enterprise Software Development Kit 12 SP5:libreoffice-sdk-7.2.3.2-48.11.4
SUSE Linux Enterprise Software Development Kit 12 SP5:libserf-1-1-1.3.9-9.5.3
SUSE Linux Enterprise Software Development Kit 12 SP5:libserf-devel-1.3.9-9.5.3

Ссылки
Уязвимость SUSE-FU-2022:0039-1