[SECURITY] Fedora 21 Update: freexl-1.0.0i-1.fc21

updates at fedoraproject.org updates at fedoraproject.org
Wed Mar 18 10:34:57 UTC 2015


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2015-3471
2015-03-09 04:42:53
--------------------------------------------------------------------------------

Name        : freexl
Product     : Fedora 21
Version     : 1.0.0i
Release     : 1.fc21
URL         : http://www.gaia-gis.it/FreeXL
Summary     : Library to extract data from within an Excel spreadsheet
Description :
FreeXL is a library to extract valid data
from within an Excel spreadsheet (.xls)

Design goals:
    * simple and lightweight
    * stable, robust and efficient
    * easily and universally portable
    * completely ignore any GUI-related oddity

--------------------------------------------------------------------------------
Update Information:

Four potentially harmful bugs causing crashes and stack corruption
were detected in FreeXL by American Fuzzy Lop and are solved in this release.

Please note: such issues are never realistically expected
to be encountered in real world XLS spreadsheets, anyway
some purposely forged XLS document could be used as a
"poisoned bait" to maliciously open a security breach.

https://groups.google.com/forum/#!topic/spatialite-users/plxKNbYw184
--------------------------------------------------------------------------------
ChangeLog:

* Fri Mar  6 2015 Volker Fröhlich <volker27 at gmx.at> 1.0.0i-1
- New release with security fixes
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1199328 - freexl-1.0.0i is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1199328
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use
su -c 'yum update freexl' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list