RE: [office-comment] ODF security hazard? (ODF all versions)

From
Alex Brown <>
Date
2009-02-21T15:15:22+00:00
ID
Thread
RE: [office-comment] ODF security hazard? (ODF all versions)
Rob hi

> But I do think this would be good to collect a set of security 
> considerations into an Appendix, as we have with Bidi techniques and 
> Accessibility guidelines.  If there is interest we could also explore 
> a "Secure ODF" profile that would forbid things like OLE embeddings, 
> scripts, etc.

That sounds like a sensible approach.

Since the DTD feature is not needed though, it is one attack vector
which could be easily blocked by forbidding DTDs ...

- Alex.