Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 14 Dec 2012 09:33:51 +0100
From: Florian Weimer <fweimer@...hat.com>
To: oss-security@...ts.openwall.com
CC: Daniel Kahn Gillmor <dkg@...thhorseman.net>,
        Kurt Seifried <kseifried@...hat.com>, Timo Warns <Warns@...-Sense.DE>
Subject: Re: Remote file inclusion by office applications

On 12/13/2012 07:53 PM, Daniel Kahn Gillmor wrote:

> For local file inclusion, libreoffice at leasts prompts me with:
>
> -----------
>   This document contains one or more links to external data.
>
>   Would you like to change the document, and update all links to get the
>   most recent data?
>
>   [Yes] [No]
> -----------
>
> but it doesn't tell me what those documents are.

This is based on a similar Microsoft Office prompt and implements 
required functionality (for different use cases involving linked 
documents).  It is not a security prompt by any means, and it predates 
macro security prompts by several years.

(I'm pretty sure Microsoft Office supports external documents with UNC 
names, FWIW.)

-- 
Florian Weimer / Red Hat Product Security Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.