-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5772-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
September 17, 2024                    https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : libreoffice
CVE ID         : CVE-2024-7788

Yufan You discovered that Libreoffice's handling of documents based on
ZIP archives was suspectible to spoofing attacks when the repair mode
attempts to address a malformed archive structure.

For additional information please refer to
https://www.libreoffice.org/about-us/security/advisories/cve-2024-7788/

For the stable distribution (bookworm), this problem has been fixed in
version 4:7.4.7-1+deb12u5.

We recommend that you upgrade your libreoffice packages.

For the detailed security status of libreoffice please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libreoffice

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

Debian: DSA-5772-1: libreoffice Security Advisory Updates

September 17, 2024
Yufan You discovered that Libreoffice's handling of documents based on ZIP archives was suspectible to spoofing attacks when the repair mode attempts to address a malformed archive...

Summary

Yufan You discovered that Libreoffice's handling of documents based on
ZIP archives was suspectible to spoofing attacks when the repair mode
attempts to address a malformed archive structure.

For additional information please refer to
https://www.libreoffice.org/about-us/security/advisories/cve-2024-7788/

For the stable distribution (bookworm), this problem has been fixed in
version 4:7.4.7-1+deb12u5.

We recommend that you upgrade your libreoffice packages.

For the detailed security status of libreoffice please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libreoffice

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
Package : libreoffice
CVE ID : CVE-2024-7788

Related News