Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Red Hat: RHSA-2017:0914-01 moderate: libreoffice file exposure

red hat
Calendar Grey April 12, 2017
Scroller Redhat
Critical announcement regarding Red Hat Enterprise Linux 7 resolves several significant concerns in libreoffice, featuring essential patches integrated.
An update for libreoffice is now available for Red Hat Enterprise Linux 7

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

All running instances of LibreOffice applications must be restarted for this update to take effect.

Summary

LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite.
Security Fix(es):
* It was found that LibreOffice disclosed contents of a file specified in an embedded object's preview. An attacker could potentially use this flaw to expose details of a system running LibreOffice as an online service via a crafted document. (CVE-2017-3157)
Bug Fix(es):
* Previously, an improper resource management caused the LibreOffice Calc spreadsheet application to terminate unexpectedly after closing a dialog window with accessibility support enabled. The resource management has been improved, and the described problem no longer occurs. (BZ#1425536)
* Previously, when an incorrect password was entered for a password protected document, the document has been considered as valid and a fallback attempt to open it as plain text has been made. As a consequence, it could appear that the document succesfully loaded, while just the encrypted unreadable content was shown. A fix has been made to terminate import attempts after entering incorrect password, and now nothing is loaded when a wrong password is entered. (BZ#1426348)
* Previously, an improper resource management caused the LibreOffice Calc spreadsheet application to terminate unexpectedly during exit, after the Text Import dialog for CSV (Comma-separated Value) files closed, when accessibility support was enabled. The resource management has been improved, and the described problem no longer occurs. (BZ#1425535)

References

https://access.redhat.com/security/cve/CVE-2017-3157 https://access.redhat.com/security/updates/classification#moderate

Package List

Red Hat Enterprise Linux Client (v. 7):
Source: libreoffice-5.0.6.2-5.el7_3.1.src.rpm
noarch: autocorr-af-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-bg-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-ca-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-cs-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-da-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-de-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-en-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-es-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-fa-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-fi-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-fr-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-ga-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-hr-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-hu-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-is-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-it-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-ja-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-ko-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-lb-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-lt-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-mn-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-nl-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-pl-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-pt-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-ro-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-ru-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-sk-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-sl-5.0.6.2-5.el7_3.1.noarch.rpm autocorr-sr-5.0.6.2-5.el7_3.1.noarch.rpm

Read the Full Advisory


Advisory ID: RHSA-2017:0914-01
Product: Red Hat Enterprise Linux
Issue date: 2017-04-12

Topic

An update for libreoffice is now available for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64

Red Hat Enterprise Linux Client Optional (v. 7) - x86_64

Red Hat Enterprise Linux Server Optional (v. 7) - aarch64, noarch, ppc64le, x86_64

Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64

Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64

Bugs Fixed

1425536 - [fix available] Crash in calc after closing dialog box with a11y enabled

1425844 - CVE-2017-3157 libreoffice: Arbitrary file disclosure in Calc and Writer

1426348 - [fix available] Password Protected (Encrypted) files opening as plain text after cancelling password dialog

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.