Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

RedHat Enterprise Linux 7: RHSA-2020:1151-01 Moderate: LibreOffice Update

red hat
Calendar Grey March 31, 2020
Dist Redhat Esm H88
Learn about the recent Red Hat announcement concerning moderate security flaws in LibreOffice, and find out the steps needed to implement necessary patches and resolve issues.
An update for libreoffice is now available for Red Hat Enterprise Linux 7

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

All running instances of LibreOffice applications must be restarted for this update to take effect.

Summary

LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite.
Security Fix(es):
* libreoffice: LibreLogo script can be manipulated into executing arbitrary python commands (CVE-2019-9848)
* libreoffice: Insufficient URL validation allowing LibreLogo script execution (CVE-2019-9850)
* libreoffice: LibreLogo global-event script execution (CVE-2019-9851)
* libreoffice: Insufficient URL encoding flaw in allowed script location check (CVE-2019-9852)
* libreoffice: Insufficient URL decoding flaw in categorizing macro location (CVE-2019-9853)
* libreoffice: Unsafe URL assembly flaw in allowed script location check (CVE-2019-9854)
* libreoffice: Remote resources protection module not applied to bullet graphics (CVE-2019-9849)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.8 Release Notes linked from the References section.

References

https://access.redhat.com/security/cve/CVE-2019-9848 https://access.redhat.com/security/cve/CVE-2019-9849 https://access.redhat.com/security/cve/CVE-2019-9850 https://access.redhat.com/security/cve/CVE-2019-9851 https://access.redhat.com/security/cve/CVE-2019-9852 https://access.redhat.com/security/cve/CVE-2019-9853 https://access.redhat.com/security/cve/CVE-2019-9854 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/7/html/7.8_release_notes/index

Package List

Red Hat Enterprise Linux Client (v. 7):
Source: libreoffice-5.3.6.1-24.el7.src.rpm
noarch: autocorr-af-5.3.6.1-24.el7.noarch.rpm autocorr-bg-5.3.6.1-24.el7.noarch.rpm autocorr-ca-5.3.6.1-24.el7.noarch.rpm autocorr-cs-5.3.6.1-24.el7.noarch.rpm autocorr-da-5.3.6.1-24.el7.noarch.rpm autocorr-de-5.3.6.1-24.el7.noarch.rpm autocorr-en-5.3.6.1-24.el7.noarch.rpm autocorr-es-5.3.6.1-24.el7.noarch.rpm autocorr-fa-5.3.6.1-24.el7.noarch.rpm autocorr-fi-5.3.6.1-24.el7.noarch.rpm autocorr-fr-5.3.6.1-24.el7.noarch.rpm autocorr-ga-5.3.6.1-24.el7.noarch.rpm autocorr-hr-5.3.6.1-24.el7.noarch.rpm autocorr-hu-5.3.6.1-24.el7.noarch.rpm autocorr-is-5.3.6.1-24.el7.noarch.rpm autocorr-it-5.3.6.1-24.el7.noarch.rpm autocorr-ja-5.3.6.1-24.el7.noarch.rpm autocorr-ko-5.3.6.1-24.el7.noarch.rpm autocorr-lb-5.3.6.1-24.el7.noarch.rpm autocorr-lt-5.3.6.1-24.el7.noarch.rpm autocorr-mn-5.3.6.1-24.el7.noarch.rpm autocorr-nl-5.3.6.1-24.el7.noarch.rpm autocorr-pl-5.3.6.1-24.el7.noarch.rpm autocorr-pt-5.3.6.1-24.el7.noarch.rpm autocorr-ro-5.3.6.1-24.el7.noarch.rpm autocorr-ru-5.3.6.1-24.el7.noarch.rpm autocorr-sk-5.3.6.1-24.el7.noarch.rpm autocorr-sl-5.3.6.1-24.el7.noarch.rpm autocorr-sr-5.3.6.1-24.el7.noarch.rpm autocorr-sv-5.3.6.1-24.el7.noarch.rpm autocorr-tr-5.3.6.1-24.el7.noarch.rpm

Read the Full Advisory


Advisory ID: RHSA-2020:1151-01
Product: Red Hat Enterprise Linux
Issue date: 2020-03-31

Topic

An update for libreoffice is now available for Red Hat Enterprise Linux 7.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64

Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64

Red Hat Enterprise Linux Server Optional (v. 7) - noarch, ppc64le, x86_64

Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64

Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch, x86_64

Bugs Fixed

1601372 - [fix available] libreoffice fails to build with --nocheck

1728763 - [fix available] block schemas completely unreadable in libreoffice writer

1737421 - CVE-2019-9849 libreoffice: Remote resources protection module not applied to bullet graphics

1737427 - CVE-2019-9848 libreoffice: LibreLogo script can be manipulated into executing arbitrary python commands

1744862 - CVE-2019-9850 libreoffice: Insufficient URL validation allowing LibreLogo script execution

1744866 - CVE-2019-9851 libreoffice: LibreLogo global-event script execution

1744868 - CVE-2019-9852 libreoffice: Insufficient URL encoding flaw in allowed script location check

1769907 - CVE-2019-9854 libreoffice: Unsafe URL assembly flaw in allowed script location check

1797466 - CVE-2019-9853 libreoffice: Insufficient URL decoding flaw in categorizing macro location

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here