Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
All running instances of LibreOffice applications must be restarted for
this update to take effect.
LibreOffice is an open source, community-developed office productivity
suite. It includes key desktop applications, such as a word processor, a
spreadsheet, a presentation manager, a formula editor, and a drawing
program. LibreOffice replaces OpenOffice and provides a similar but
enhanced and extended office suite.
The following packages have been upgraded to a newer upstream version:
libreoffice (5.0.6.2). (BZ#1290148)
Security Fix(es):
* Multiple flaws were found in the Lotus Word Pro (LWP) document format
parser in LibreOffice. By tricking a user into opening a specially crafted
LWP document, an attacker could possibly use this flaw to execute arbitrary
code with the privileges of the user opening the file. (CVE-2016-0794,
CVE-2016-0795)
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 7.3 Release Notes linked from the References section.
https://access.redhat.com/security/cve/CVE-2016-0794 https://access.redhat.com/security/cve/CVE-2016-0795 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/Red_Hat_Enterprise_Linux/7/html/7.3_Release_Notes/index.html
Red Hat Enterprise Linux Client (v. 7):
Source:
libcmis-0.5.1-2.el7.src.rpm
libpagemaker-0.0.3-1.el7.src.rpm
libreoffice-5.0.6.2-3.el7.src.rpm
noarch:
autocorr-af-5.0.6.2-3.el7.noarch.rpm
autocorr-bg-5.0.6.2-3.el7.noarch.rpm
autocorr-ca-5.0.6.2-3.el7.noarch.rpm
autocorr-cs-5.0.6.2-3.el7.noarch.rpm
autocorr-da-5.0.6.2-3.el7.noarch.rpm
autocorr-de-5.0.6.2-3.el7.noarch.rpm
autocorr-en-5.0.6.2-3.el7.noarch.rpm
autocorr-es-5.0.6.2-3.el7.noarch.rpm
autocorr-fa-5.0.6.2-3.el7.noarch.rpm
autocorr-fi-5.0.6.2-3.el7.noarch.rpm
autocorr-fr-5.0.6.2-3.el7.noarch.rpm
autocorr-ga-5.0.6.2-3.el7.noarch.rpm
autocorr-hr-5.0.6.2-3.el7.noarch.rpm
autocorr-hu-5.0.6.2-3.el7.noarch.rpm
autocorr-is-5.0.6.2-3.el7.noarch.rpm
autocorr-it-5.0.6.2-3.el7.noarch.rpm
autocorr-ja-5.0.6.2-3.el7.noarch.rpm
autocorr-ko-5.0.6.2-3.el7.noarch.rpm
autocorr-lb-5.0.6.2-3.el7.noarch.rpm
autocorr-lt-5.0.6.2-3.el7.noarch.rpm
autocorr-mn-5.0.6.2-3.el7.noarch.rpm
autocorr-nl-5.0.6.2-3.el7.noarch.rpm
autocorr-pl-5.0.6.2-3.el7.noarch.rpm
autocorr-pt-5.0.6.2-3.el7.noarch.rpm
autocorr-ro-5.0.6.2-3.el7.noarch.rpm
autocorr-ru-5.0.6.2-3.el7.noarch.rpm
autocorr-sk-5.0.6.2-3.el7.noarch.rpm
autocorr-sl-5.0.6.2-3.el7.noarch.rpm
autocorr-sr-5.0.6.2-3.el7.noarch.rpm
autocorr-sv-5.0.6.2-3.el7.noarch.rpm
Read the Full Advisory
An update for libreoffice is now available for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - aarch64, noarch, ppc64le, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch, x86_64
1161240 - [fix available]Master Slide Elements of Footer, Number, and Date are not delectable easily
1168757 - [fix available] Selecting multiple slides is not reflected in Print dialog
1238413 - [abrt] [fix-available] libreoffice-core: SfxViewFrame::GetFrame() const(): soffice.bin killed by SIGSEGV
1255811 - [fix available] Calc: Random Number generator can't be edited and applied for cell location
1256843 - [fix available] In Start Center, if you open Templates, there is no "Close" or "X" in upper right corner of Templates dialog box.
1257635 - [fix available] sometimes LO doesn't see cups printers1263949 - [fix available] Writer fails to open correct ODT file from WebDAV share
1290148 - rebase to libreoffice 5.0 in RHEL 7.3
1290152 - rebase libcmis to 0.5.0
1290153 - rebase mdds to 0.12.1
1306609 - CVE-2016-0794 CVE-2016-0795 libreoffice: Multiple out-of-bounds overflows in lwp filter
1330591 - [fix available] Not able to add RH Google Drive as a server
Get the latest Linux and open source security news straight to your inbox.