This update for libreoffice fixes the following issues:
Updated to version 6.2.7.1.
Security issues fixed:
- CVE-2019-9849: Disabled fetching remote bullet graphics in 'stealth
mode' (bsc#1141861).
- CVE-2019-9848: Fixed an arbitrary script execution via LibreLogo
(bsc#1141862).
- CVE-2019-9851: Fixed LibreLogo global-event script execution issue
(bsc#1146105).
- CVE-2019-9852: Fixed insufficient URL encoding flaw in allowed script
location check (bsc#1146107).
- CVE-2019-9850: Fixed insufficient URL validation that allowed LibreLogo
script execution (bsc#1146098).
- CVE-2019-9854: Fixed unsafe URL assembly flaw (bsc#1149944).
- CVE-2019-9855: Fixed path equivalence handling flaw (bsc#1149943)
Non-security issue fixed:
- SmartArt: Basic rendering of Trapezoid List (bsc#1133534).
This update was imported from the SUSE:SLE-15-SP1:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2019-2183=1
- openSUSE Leap 15.1 (x86_64):
libreoffice-6.2.7.1-lp151.3.6.1
libreoffice-base-6.2.7.1-lp151.3.6.1
libreoffice-base-debuginfo-6.2.7.1-lp151.3.6.1
libreoffice-base-drivers-firebird-6.2.7.1-lp151.3.6.1
libreoffice-base-drivers-firebird-debuginfo-6.2.7.1-lp151.3.6.1
libreoffice-base-drivers-postgresql-6.2.7.1-lp151.3.6.1
libreoffice-base-drivers-postgresql-debuginfo-6.2.7.1-lp151.3.6.1
libreoffice-calc-6.2.7.1-lp151.3.6.1
libreoffice-calc-debuginfo-6.2.7.1-lp151.3.6.1
libreoffice-calc-extensions-6.2.7.1-lp151.3.6.1
libreoffice-debuginfo-6.2.7.1-lp151.3.6.1
libreoffice-debugsource-6.2.7.1-lp151.3.6.1
libreoffice-draw-6.2.7.1-lp151.3.6.1
libreoffice-draw-debuginfo-6.2.7.1-lp151.3.6.1
libreoffice-filters-optional-6.2.7.1-lp151.3.6.1
libreoffice-gnome-6.2.7.1-lp151.3.6.1
libreoffice-gnome-debuginfo-6.2.7.1-lp151.3.6.1
libreoffice-gtk2-6.2.7.1-lp151.3.6.1
libreoffice-gtk2-debuginfo-6.2.7.1-lp151.3.6.1
libreoffice-gtk3-6.2.7.1-lp151.3.6.1
libreoffice-gtk3-debuginfo-6.2.7.1-lp151.3.6.1
libreoffice-impress-6.2.7.1-lp...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2019-9848.html
https://www.suse.com/security/cve/CVE-2019-9849.html
https://www.suse.com/security/cve/CVE-2019-9850.html
https://www.suse.com/security/cve/CVE-2019-9851.html
https://www.suse.com/security/cve/CVE-2019-9852.html
https://www.suse.com/security/cve/CVE-2019-9854.html
https://www.suse.com/security/cve/CVE-2019-9855.html
https://bugzilla.suse.com/1133534
https://bugzilla.suse.com/1141861
https://bugzilla.suse.com/1141862
https://bugzilla.suse.com/1146098
https://bugzilla.suse.com/1146105
https://bugzilla.suse.com/1146107
https://bugzilla.suse.com/1149943
https://bugzilla.suse.com/1149944
--
Get the latest Linux and open source security news straight to your inbox.