- -------------------------------------------------------------------------
Debian Security Advisory DSA-3163-1                   security@debian.org
http://www.debian.org/security/                        Alessandro Ghedini
February 19, 2015                      http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : libreoffice
CVE ID         : CVE-2014-9093
Debian Bug     : 771163

It was discovered that LibreOffice, an office productivity suite, could
try to write to invalid memory areas when importing malformed RTF files.
This could allow remote attackers to cause a denial of service (crash)
or arbitrary code execution via crafted RTF files.

For the stable distribution (wheezy), this problem has been fixed in
version 1:3.5.4+dfsg2-0+deb7u3.

For the upcoming stable distribution (jessie), this problem has been
fixed in version 1:4.3.3-2.

For the unstable distribution (sid), this problem has been fixed in
version 1:4.3.3-2.

We recommend that you upgrade your libreoffice packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

Debian: DSA-3163-1: libreoffice security update

February 19, 2015
It was discovered that LibreOffice, an office productivity suite, could try to write to invalid memory areas when importing malformed RTF files

Summary

For the stable distribution (wheezy), this problem has been fixed in
version 1:3.5.4+dfsg2-0+deb7u3.

For the upcoming stable distribution (jessie), this problem has been
fixed in version 1:4.3.3-2.

For the unstable distribution (sid), this problem has been fixed in
version 1:4.3.3-2.

We recommend that you upgrade your libreoffice packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
Package : libreoffice
CVE ID : CVE-2014-9093

Related News