Red Hat Bugzilla – Bug 871462
[fix available] Libreoffice version in RHEL6 triggers various anti-virus software
Last modified: 2013-11-21 05:04:00 EST
Libreoffice contains a number of harmless files used for testing purposes but these files trigger various AV software such as "Microsoft Security Essentials" with serious warnings. This means that anyone scanning our source ISO with these tools will receive false positive virus alerts. Upstream received lots of comments about this and decided to alter the files so they were not longer triggers; see http://cgit.freedesktop.org/libreoffice/core/patch/sw/qa/core/data/ww8/pass/?id=e898bcc1c2f2d227d8b638dfbee01e393562e142 We should do the same for the next ASYNC libreoffice or RHEL6.4 whichever is earliest.
See also http://lists.freedesktop.org/archives/libreoffice/2011-September/018749.html https://bugs.freedesktop.org/show_bug.cgi?id=42655
(In reply to comment #0) > Upstream received lots of comments about this and decided to alter the files > so they were not longer triggers; see > http://cgit.freedesktop.org/libreoffice/core/patch/sw/qa/core/data/ww8/pass/ > ?id=e898bcc1c2f2d227d8b638dfbee01e393562e142 A better link to a complete commit including decoding code: http://cgit.freedesktop.org/libreoffice/core/commit/?id=e898bcc1c2f2d227d8b638dfbee01e393562e142
doable, seeing as did it upstream already
FWIW what we'd have to do (assuming that we're not going to rebase in 6.4 to a later version, which I think is a given for the moment) is to backport my decrypt-on-the-fly-during-tests code and then unpack the sources, crypt the offending docs, and repack the sources in order to not have the raw files in the .src.rpms
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2013-1594.html