Bug 40265

Summary: After Git clone Microsoft Security Essential reports potential threats
Product: LibreOffice Reporter: mail
Component: LibreOfficeAssignee: Not Assigned <libreoffice-bugs>
Status: RESOLVED FIXED    
Severity: normal CC: detective.conan.1412, LibreOffice
Priority: medium    
Version: Master old -3.6   
Hardware: x86 (IA32)   
OS: Windows (All)   
Whiteboard:
Crash report or crash signature: Regression By:

Description mail 2011-08-21 02:58:39 UTC
git clone git://anongit.freedesktop.org/libreoffice/core
--

Category: Trojan [Win32/Controlwod.c]

Description: This program is dangerous and executes commands from an attacker.

Recommended action: Remove this software immediately.

Security Essentials detected programs that may compromise your privacy or damage your computer. You can still access the files that these programs use without removing them (not recommended). To access these files, select the Allow action and click Apply actions. If this option is not available, log on as administrator or ask the security administrator for help.

Items: 
file:C:\Users\any\projects\libreoffice\core\sw\qa\core\data\ww8\pass\CVE-2006-6561-1.doc
file:C:\Users\any\projects\libreoffice\core\sw\qa\core\data\ww8\pass\CVE-2006-6628-1.doc

Is this a false alarm? (Similar threats are reported for 9 potential threat sources...) Has anyone checked these already?
Comment 1 Rainer Bielefeld Retired 2011-09-03 23:02:09 UTC
@mail@tamas-nagy.net:
Please contribute a step by step instruction how a normal user without git account can reproduce the problem.
Comment 2 mail 2011-09-04 06:47:49 UTC
No Git Account is necessary, see first line in the bug report. Obviously, this could be some macro virused in the repository or a Microsoft SE bug... Which one is that?

(In reply to comment #1)
> @mail@tamas-nagy.net:
> Please contribute a step by step instruction how a normal user without git
> account can reproduce the problem.
Comment 3 Rainer Bielefeld Retired 2011-09-14 01:00:01 UTC
I doubt that anybody will proceed this without requested information, so closed.
Comment 4 Korrawit Pruegsanusak 2011-10-07 23:33:18 UTC
@Reporter:
For your information, Caolán has fixed this in master.
http://cgit.freedesktop.org/libreoffice/core/commit/?id=e898bcc1c2f2d227d8b638dfbee01e393562e142
You can try ./g pull -r, and this issue should disappear. Thanks!

Mark as FIXED.