Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

openSUSE Leap 42.3: 2018:1311-1 Moderate: LibreOffice Denial of Service

opensuse
Calendar Grey May 17, 2018
Scroller Opensuse
A security patch for LibreOffice resolves issues that could allow remote exploitation on openSUSE platforms.
An update that solves two vulnerabilities and has three fixes is now available.

Description

This update for libreoffice to 6.0.4.2 fixes lots of bugs and also the

following issues:

Security issues fixed:

- CVE-2018-10120: The SwCTBWrapper::Read function in

sw/source/filter/ww8/ww8toolbar.cxx did not validate a customizations

index, which allowed remote attackers to cause a denial of service

(heap-based buffer overflow with write access) or possibly have

unspecified other impact via a crafted document that contains a certain

Microsoft Word record. (bsc#1089706)

- CVE-2018-10119: sot/source/sdstor/stgstrms.cxx used an incorrect integer

data type in the StgSmallStrm class, which allowed remote attackers to

cause a denial of service (use-after-free with write access) or possibly

have unspecified other impact via a crafted document that uses the

structured storage ole2 wrapper file format. (bsc#1089705)

Other issues fixed:

- DOCX import: missing table background color

- Bring back offline help per popular...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-467=1

Package List

- openSUSE Leap 42.3 (x86_64):

libreoffice-6.0.4.2-21.1

libreoffice-base-6.0.4.2-21.1

libreoffice-base-debuginfo-6.0.4.2-21.1

libreoffice-base-drivers-mysql-6.0.4.2-21.1

libreoffice-base-drivers-mysql-debuginfo-6.0.4.2-21.1

libreoffice-base-drivers-postgresql-6.0.4.2-21.1

libreoffice-base-drivers-postgresql-debuginfo-6.0.4.2-21.1

libreoffice-calc-6.0.4.2-21.1

libreoffice-calc-debuginfo-6.0.4.2-21.1

libreoffice-calc-extensions-6.0.4.2-21.1

libreoffice-debuginfo-6.0.4.2-21.1

libreoffice-debugsource-6.0.4.2-21.1

libreoffice-draw-6.0.4.2-21.1

libreoffice-draw-debuginfo-6.0.4.2-21.1

libreoffice-filters-optional-6.0.4.2-21.1

libreoffice-gnome-6.0.4.2-21.1

libreoffice-gnome-debuginfo-6.0.4.2-21.1

libreoffice-gtk2-6.0.4.2-21.1

libreoffice-gtk2-debuginfo-6.0.4.2-21.1

libreoffice-gtk3-6.0.4.2-21.1

libreoffice-gtk3-debuginfo-6.0.4.2-21.1

libreoffice-impress-6.0.4.2-21.1

libreoffice-impress-debuginfo-6.0.4.2-21.1

libreoffice-kde4-6.0.4.2-21.1

libreoffice-kde4-debuginfo-6.0.4.2-21.1

libreoffice-mailmerge-6.0.4.2-21.1

libreof...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-10119.html

https://www.suse.com/security/cve/CVE-2018-10120.html

https://bugzilla.suse.com/1089705

https://bugzilla.suse.com/1089706

https://bugzilla.suse.com/1090737

https://bugzilla.suse.com/1091772

https://bugzilla.suse.com/915996

--

Announcement ID: openSUSE-SU-2018:1311-1
Rating: moderate
Affected Products: openSUSE Leap 42.3 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.