|
Message-ID: <50CAE46F.3000200@redhat.com> Date: Fri, 14 Dec 2012 09:33:51 +0100 From: Florian Weimer <fweimer@...hat.com> To: oss-security@...ts.openwall.com CC: Daniel Kahn Gillmor <dkg@...thhorseman.net>, Kurt Seifried <kseifried@...hat.com>, Timo Warns <Warns@...-Sense.DE> Subject: Re: Remote file inclusion by office applications On 12/13/2012 07:53 PM, Daniel Kahn Gillmor wrote: > For local file inclusion, libreoffice at leasts prompts me with: > > ----------- > This document contains one or more links to external data. > > Would you like to change the document, and update all links to get the > most recent data? > > [Yes] [No] > ----------- > > but it doesn't tell me what those documents are. This is based on a similar Microsoft Office prompt and implements required functionality (for different use cases involving linked documents). It is not a security prompt by any means, and it predates macro security prompts by several years. (I'm pretty sure Microsoft Office supports external documents with UNC names, FWIW.) -- Florian Weimer / Red Hat Product Security Team
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.