Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian Buster DLA-3703-1 Severe: LibreOffice Multiple Threats and Fixes

debian lts
Calendar Grey December 31, 2023
Dist Debian Esm H88
Debian LTS notice DLA-3704-1 mitigates multiple security weaknesses within LibreOffice, improving safety for users.
Multiple vulnerabilities have been discovered in LibreOffice an office productivity software suite: CVE-2020-12801

Summary

CVE-2020-12801

If LibreOffice has an encrypted document
open and crashes, that document is auto-saved encrypted.
On restart, LibreOffice offers to restore the document
and prompts for the password to decrypt it. If the recovery
is successful, and if the file format of the recovered document
was not LibreOffice's default ODF file format, then affected versions
of LibreOffice default that subsequent saves of the document
are unencrypted. This may lead to a user accidentally saving
a MSOffice file format document unencrypted while believing
it to be encrypted.

CVE-2020-12802

LibreOffice has a 'stealth mode' in which only
documents from locations deemed 'trusted' are allowed to
retrieve remote resources. This mode is not the default mode,
but can be enabled by users who want to disable LibreOffice's ability
to include remote resources within a document. A flaw existed
where remote graphic links loaded from docx documents were omitted

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: libreoffice
Version: 1:6.1.5-3+deb10u11
CVE ID: CVE-2020-12801 CVE-2020-12802 CVE-2020-12803 CVE-2023-6185

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here