IBM Lotus Symphony 3 Fix Pack 2 release notes
IBM Lotus Symphony 3 Fix Pack 2 contains fixes for a few critical security vulnerability issues and other low risk, high impact fixes. This document provides detailed installation information and lists the major fixes contained in the fix pack.
Before You Install Fix Pack 2
Before you install the fix pack, first check whether Lotus Symphony 3 or Lotus Symphony 3 with Fix Pack 1 is installed. If not installed, the installation is halted and an error prompts that it is unable to find a valid target platform.
To confirm whether version 3 is installed
-
Click Help > About IBM Lotus Symphony. On Mac OS X, click IBM Lotus Symphony > About IBM Lotus Symphony. The About IBM Lotus Symphony window opens.
- Check the Release and Revision numbers:
- If the Release number is 3.0.0 FP1, you have installed Lotus Symphony 3 with Fix Pack 1 and you can install IBM Lotus Symphony 3 Fix Pack 2 directly.
- If the Release number is 3.0.0, you have installed Lotus Symphony 3. Next, check whether the Revision number is 20101015.2340. If it is that number, you can directly install Fix Pack 2. Otherwise, you need to download that version from the website, install it, and then install this fix pack.
Back to top
Installing or uninstalling Fix Pack 2 on Windows Operating Systems
Installation instructions
You can use any of the following ways to install the fix pack: follow a graphic wizard to install using a GUI, install it using a command line or install it in silent mode without any user interactions.
To install using a GUI:
- Download Fix Pack 2 to a folder on your hard disk.
- Double-click the Lotus_Symphony3_fp2.exe file and follow the wizard to complete the installation.
- To verify that the installation is complete, click Help > About IBM Lotus Symphony and notice that the release number is changed to 3.0.0 FP2.
To force installation:
- Download Fix Pack 2 to a folder on your hard disk and open a command window.
- Enter the following command: Lotus_Symphony3_fp2.exe /s /a /s /v"HOTFIXACTION=INSTALL".
To install in silent mode:
- Download Fix Pack 2 to a folder on your hard disk and open a command window.
- Enter the following command: Lotus_Symphony3_fp2.exe /s /a /s /v"/lv c:\installogs.txt HOTFIXACTION=INSTALL /qn"
The log file installlogs.txt is created after installation. It is located in the same folder where you downloaded the fix pack.
Uninstallation instructions
To uninstall using a GUI:
- Locate the Lotus_Symphony3_fp2.exe file in the folder where you downloaded the fix pack.
- Double-click the Lotus_Symphony3_fp2.exe file and follow the wizard to complete the uninstallation.
To uninstall in silent Unistallation mode:
- Open a command window.
- Enter the following command: Lotus_Symphony3_fp2.exe /s /a /s /v"/lv c:\installogs.txt HOTFIXACTION=UNINSTALL /qn"
The log file installlogs.txt will is created after uninstallation. It is located in the same folder where you downloaded the fix pack.
Back to top
Installing or uninstalling Fix Pack 2 on SuSe and Redhat Operating Systems
Installation instructions:
To install using a GUI:
- Download Fix Pack 2 to a folder on your hard disk.
- Double-click the lotus_symphony3_fp2.i586.rpm file and follow the instructions to complete the installation.
- To verify that the installation is complete, click Help > About IBM Lotus Symphony and notice that the release number is changed to 3.0.0 FP2.
To install using a command line:
- Download Fix Pack 2 to a folder on your hard disk.
- Open a terminal window and locate the file that you downloaded.
- If the IBM Lotus Symphony Release is 3.0.0, enter: sudo rpm -ihv lotus_symphony3_fp2.i586.rpm
- If the IBM Lotus Symphony Release is 3.0.0 FP1, enter: sudo rpm -Uvh lotus_symphony3_fp2.i586.rpm
Uninstallation instructions:
Open a terminal window and enter: sudo rpm -e symphony_fixpack.
Back to top
Installing or uninstalling Fix Pack 2 on Ubuntu Operating Systems
Installation instructions:
To install using a GUI:
- Download Fix Pack 2 to a folder on your hard disk.
- Double-click the lotus_symphony3_fp2.i386.deb file and follow the instructions to complete the installation.
To install using a command line:
- Download Fix Pack 2 to a folder on your hard disk.
- Open a terminal and locate the file that you download, run the command: sudo dpkg -i lotus_symphony3_fp2.i386.deb
- To verify that the installation is complete, click Help > About IBM Lotus Symphony and notice that the release number is changed to 3.0.0 FP2
Unistallation instructions:
Open a terminal window and enter: sudo dpkg -P symphony-fixpack.
Back to top
Installing or uninstall Fix Pack 2 on Mac OS X Operating Systems
Installation instructions:
To install using a GUI:
- Download Fix Pack 2 to a folder on your hard disk and extract it.
- Double-click the Lotus_Symphony_Fixpack.pkg file and follow the instructions to complete the installation.
- To verify that the installation is complete, click IBM Lotus Symphony > About IBM Lotus Symphony and notice that the release number is changed to 3.0.0 FP2
To install using a command line:
- Open a terminal and locate the Lotus_Symphony_Fixpack.pkg file.
- Enter the command: sudo installer -pkg Lotus_Symphony_Fixpack.pkg -target /Applications/
Unistallation instructions:
To unistall this fix pack, you must belong to the admin group and you must be the same person who installed this package.
- Open a terminal and locate the hotfixUninstall file that you extracted when installing.
- Enter the command: sudo ./hotfixUninstall
Back to top
Frequently asked questions:
Question:Fix Pack 1 also contains many fixes, do we need install both Fix Pack 1 separately from Fix Pack 2 to get all the fixes?
Answer: No, Lotus Symphony 3 Fix Pack 2 contains all of the fixes in Fix Pack 1 and after installation, it replaces the Fix Pack 1.
Question:What is a fix pack for? Are there any differences between formal release and a fix pack?
Answer: Fix packs are released periodically between major or maintenance versions to provide a greater level of stability. Fix packs go through the same level, regression and interoperability testing that occurs with maintenance versions. Fix packs are always cumulative and contain all of the fixes from previous ones.
Question:I am not an English user. Do I have to install the fix pack in my native language version?
Answer: No, fix packs are language independent and can be applied to any language version of Lotus Symphony 3.
Question: I am using Lotus Symphony language packages for Ubuntu, SuSe and Redhat. What is the sequence for installing or un-installing the fix pack and language packages?
Answer:
- For installation, make sure the language packages are installed first. If the sequence is reversed, you must uninstall Fix Pack 2, install the language packages, and then you are able to install Fix Pack 2.
- To uninstall the languages packages, make sure that Fix Pack 2 is uninstalled first.
Question: What happens when I uninstall Fix Pack 2?
Answer:After uninstalling Fix Pack 2, the code level of Lotus Symphony is rolled back to version 3 directly. To roll back to Fix Pack 1, uninstall Fix Pack 2 and then install Fix Pack 1 again.
Back to top
Fixes contained in Fix Pack 2:
- CVE-2010-4643: A security vulnerability in OpenOffice.org that is related to TGA file processing might lead to arbitrary code execution.
- CVE-2010-3689: The OpenOffice.org start script and other shell scripts expand the LD_LIBRARY_PATH in an insecure way.
- CVE-2010-2935 / CVE-2010-2936: A security vulnerability in OpenOffice.org that is related to PowerPoint document processing might lead to arbitrary code execution.
- CVE-2010-4253: A security vulnerability in OpenOffice.org that is related to PNG file processing might lead to arbitrary code execution.
- CVE-2010-3453 / CVE-2010-3454: A security vulnerability in OpenOffice.org which is related to Word document processing might lead to arbitrary code execution.
CVE-2010-3451 / CVE-2010-3452: A security vulnerability in OpenOffice.org which is related to RTF document processing might lead to arbitrary code execution.
- CVE-2010-4008 / CVE-2010-4494: a possible security vulnerability in OpenOffice.org resulting from the independent library LIBXML2
- CVE-2010-3450: A directory traversal vulnerability in OpenOffice.org that is related to ZIP or JAR package extraction might lead to overwriting files and arbitrary code execution.
- SPR #JCHC89R945: XPD62FP5: Cross-site scripting high security issue in AppScan.
- SPR #MSTO89WRX8: LWI - Security hole with selective access control support.
- SPR #BLIE8E3MH7: Add mechanism to web container to turn off web applications.
- PPT files with grouped objects are corrupted if they are saved and then opened again in Microsoft Office when it contains a security patch claimed in Microsoft Security Bulletin MS10-087. For detailed patch information, see http://www.microsoft.com/technet/security/bulletin/ms10-087.mspx.
- Optimized preload notification behavior by removing the notification bubble.
- Password protected Microsoft Excel with edit password cannot be edited.
- The cell border orientation is lost when opening a Microsoft Excel file.
- The result is wrong when copying a table that contains hidden columns from Lotus Symphony Spreadsheets to Lotus Notes.
- The behavior of Subtotal in DataPilot is wrong when there is more than one item in the Data area.
- The 'divide by 1000' format is not supported in Lotus Symphony 3 Spreadsheet.
Back to top