Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Red Hat Enterprise Linux 8: RHSA-2020-1598-01 Moderate Security Update

red hat
Calendar Grey April 28, 2020
Dist Redhat Esm H88
Update now ready for Red Hat Enterprise Linux 8: Important security patch addressing libreoffice vulnerabilities. System restart necessary.
An update for libreoffice is now available for Red Hat Enterprise Linux 8

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

All running instances of LibreOffice applications must be restarted for this update to take effect.

Summary

LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite.
Security Fix(es):
* libreoffice: Insufficient URL validation allowing LibreLogo script execution (CVE-2019-9850)
* libreoffice: LibreLogo global-event script execution (CVE-2019-9851)
* libreoffice: Insufficient URL encoding flaw in allowed script location check (CVE-2019-9852)
* libreoffice: Insufficient URL decoding flaw in categorizing macro location (CVE-2019-9853)
* libreoffice: Unsafe URL assembly flaw in allowed script location check (CVE-2019-9854)
* libreoffice: Remote resources protection module not applied to bullet graphics (CVE-2019-9849)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.2 Release Notes linked from the References section.

References

https://access.redhat.com/security/cve/CVE-2019-9849 https://access.redhat.com/security/cve/CVE-2019-9850 https://access.redhat.com/security/cve/CVE-2019-9851 https://access.redhat.com/security/cve/CVE-2019-9852 https://access.redhat.com/security/cve/CVE-2019-9853 https://access.redhat.com/security/cve/CVE-2019-9854 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.2_release_notes/index

Package List

Red Hat Enterprise Linux AppStream (v. 8):
Source: libreoffice-6.0.6.1-20.el8.src.rpm
noarch: autocorr-af-6.0.6.1-20.el8.noarch.rpm autocorr-bg-6.0.6.1-20.el8.noarch.rpm autocorr-ca-6.0.6.1-20.el8.noarch.rpm autocorr-cs-6.0.6.1-20.el8.noarch.rpm autocorr-da-6.0.6.1-20.el8.noarch.rpm autocorr-de-6.0.6.1-20.el8.noarch.rpm autocorr-en-6.0.6.1-20.el8.noarch.rpm autocorr-es-6.0.6.1-20.el8.noarch.rpm autocorr-fa-6.0.6.1-20.el8.noarch.rpm autocorr-fi-6.0.6.1-20.el8.noarch.rpm autocorr-fr-6.0.6.1-20.el8.noarch.rpm autocorr-ga-6.0.6.1-20.el8.noarch.rpm autocorr-hr-6.0.6.1-20.el8.noarch.rpm autocorr-hu-6.0.6.1-20.el8.noarch.rpm autocorr-is-6.0.6.1-20.el8.noarch.rpm autocorr-it-6.0.6.1-20.el8.noarch.rpm autocorr-ja-6.0.6.1-20.el8.noarch.rpm autocorr-ko-6.0.6.1-20.el8.noarch.rpm autocorr-lb-6.0.6.1-20.el8.noarch.rpm autocorr-lt-6.0.6.1-20.el8.noarch.rpm autocorr-mn-6.0.6.1-20.el8.noarch.rpm autocorr-nl-6.0.6.1-20.el8.noarch.rpm autocorr-pl-6.0.6.1-20.el8.noarch.rpm autocorr-pt-6.0.6.1-20.el8.noarch.rpm autocorr-ro-6.0.6.1-20.el8.noarch.rpm autocorr-ru-6.0.6.1-20.el8.noarch.rpm autocorr-sk-6.0.6.1-20.el8.noarch.rpm autocorr-sl-6.0.6.1-20.el8.noarch.rpm autocorr-sr-6.0.6.1-20.el8.noarch.rpm autocorr-sv-6.0.6.1-20.el8.noarch.rpm autocorr-tr-6.0.6.1-20.el8.noarch.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2020:1598-01
Product: Red Hat Enterprise Linux
Issue date: 2020-04-28

Topic

An update for libreoffice is now available for Red Hat Enterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat CodeReady Linux Builder (v. 8) - aarch64, noarch, ppc64le, x86_64

Red Hat Enterprise Linux AppStream (v. 8) - noarch, ppc64le, x86_64

Bugs Fixed

1648281 - [libreoffice][fix available] Junk character gets added when some emojis are inserted.

1737421 - CVE-2019-9849 libreoffice: Remote resources protection module not applied to bullet graphics

1744862 - CVE-2019-9850 libreoffice: Insufficient URL validation allowing LibreLogo script execution

1744866 - CVE-2019-9851 libreoffice: LibreLogo global-event script execution

1744868 - CVE-2019-9852 libreoffice: Insufficient URL encoding flaw in allowed script location check

1769907 - CVE-2019-9854 libreoffice: Unsafe URL assembly flaw in allowed script location check

1797466 - CVE-2019-9853 libreoffice: Insufficient URL decoding flaw in categorizing macro location

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here