SUSE Security Update: Security update for libreoffice
______________________________________________________________________________

Announcement ID:    SUSE-SU-2018:1296-1
Rating:             moderate
References:         #1089705 #1089706 #1090737 #1091772 #915996 
                    
Cross-References:   CVE-2018-10119 CVE-2018-10120
Affected Products:
                    SUSE Linux Enterprise Workstation Extension 12-SP3
                    SUSE Linux Enterprise Software Development Kit 12-SP3
                    SUSE Linux Enterprise Desktop 12-SP3
______________________________________________________________________________

   An update that solves two vulnerabilities and has three
   fixes is now available.

Description:



   This update for libreoffice to 6.0.4.2 fixes lots of bugs and also the
   following issues:

   Security issues fixed:

   - CVE-2018-10120: The SwCTBWrapper::Read function in
     sw/source/filter/ww8/ww8toolbar.cxx did not validate a customizations
     index, which allowed remote attackers to cause a denial of service
     (heap-based buffer overflow with write access) or possibly have
     unspecified other impact via a crafted document that contains a certain
     Microsoft Word record. (bsc#1089706)
   - CVE-2018-10119: sot/source/sdstor/stgstrms.cxx used an incorrect integer
     data type in the StgSmallStrm class, which allowed remote attackers to
     cause a denial of service (use-after-free with write access) or possibly
     have unspecified other impact via a crafted document that uses the
     structured storage ole2 wrapper file format.  (bsc#1089705)

   Other issues fixed:

   - DOCX import: missing table background color
   - Bring back offline help per popular demand as lto saves space we could
     use with it bsc#915996


Patch Instructions:

   To install this SUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Workstation Extension 12-SP3:

      zypper in -t patch SUSE-SLE-WE-12-SP3-2018-913=1

   - SUSE Linux Enterprise Software Development Kit 12-SP3:

      zypper in -t patch SUSE-SLE-SDK-12-SP3-2018-913=1

   - SUSE Linux Enterprise Desktop 12-SP3:

      zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2018-913=1



Package List:

   - SUSE Linux Enterprise Workstation Extension 12-SP3 (x86_64):

      libreoffice-6.0.4.2-43.33.1
      libreoffice-base-6.0.4.2-43.33.1
      libreoffice-base-debuginfo-6.0.4.2-43.33.1
      libreoffice-base-drivers-mysql-6.0.4.2-43.33.1
      libreoffice-base-drivers-mysql-debuginfo-6.0.4.2-43.33.1
      libreoffice-base-drivers-postgresql-6.0.4.2-43.33.1
      libreoffice-base-drivers-postgresql-debuginfo-6.0.4.2-43.33.1
      libreoffice-calc-6.0.4.2-43.33.1
      libreoffice-calc-debuginfo-6.0.4.2-43.33.1
      libreoffice-calc-extensions-6.0.4.2-43.33.1
      libreoffice-debuginfo-6.0.4.2-43.33.1
      libreoffice-debugsource-6.0.4.2-43.33.1
      libreoffice-draw-6.0.4.2-43.33.1
      libreoffice-draw-debuginfo-6.0.4.2-43.33.1
      libreoffice-filters-optional-6.0.4.2-43.33.1
      libreoffice-gnome-6.0.4.2-43.33.1
      libreoffice-gnome-debuginfo-6.0.4.2-43.33.1
      libreoffice-gtk2-6.0.4.2-43.33.1
      libreoffice-gtk2-debuginfo-6.0.4.2-43.33.1
      libreoffice-impress-6.0.4.2-43.33.1
      libreoffice-impress-debuginfo-6.0.4.2-43.33.1
      libreoffice-mailmerge-6.0.4.2-43.33.1
      libreoffice-math-6.0.4.2-43.33.1
      libreoffice-math-debuginfo-6.0.4.2-43.33.1
      libreoffice-officebean-6.0.4.2-43.33.1
      libreoffice-officebean-debuginfo-6.0.4.2-43.33.1
      libreoffice-pyuno-6.0.4.2-43.33.1
      libreoffice-pyuno-debuginfo-6.0.4.2-43.33.1
      libreoffice-writer-6.0.4.2-43.33.1
      libreoffice-writer-debuginfo-6.0.4.2-43.33.1
      libreoffice-writer-extensions-6.0.4.2-43.33.1

   - SUSE Linux Enterprise Workstation Extension 12-SP3 (noarch):

      libreoffice-branding-upstream-6.0.4.2-43.33.1
      libreoffice-icon-themes-6.0.4.2-43.33.1
      libreoffice-l10n-af-6.0.4.2-43.33.1
      libreoffice-l10n-ar-6.0.4.2-43.33.1
      libreoffice-l10n-bg-6.0.4.2-43.33.1
      libreoffice-l10n-ca-6.0.4.2-43.33.1
      libreoffice-l10n-cs-6.0.4.2-43.33.1
      libreoffice-l10n-da-6.0.4.2-43.33.1
      libreoffice-l10n-de-6.0.4.2-43.33.1
      libreoffice-l10n-en-6.0.4.2-43.33.1
      libreoffice-l10n-es-6.0.4.2-43.33.1
      libreoffice-l10n-fi-6.0.4.2-43.33.1
      libreoffice-l10n-fr-6.0.4.2-43.33.1
      libreoffice-l10n-gu-6.0.4.2-43.33.1
      libreoffice-l10n-hi-6.0.4.2-43.33.1
      libreoffice-l10n-hr-6.0.4.2-43.33.1
      libreoffice-l10n-hu-6.0.4.2-43.33.1
      libreoffice-l10n-it-6.0.4.2-43.33.1
      libreoffice-l10n-ja-6.0.4.2-43.33.1
      libreoffice-l10n-ko-6.0.4.2-43.33.1
      libreoffice-l10n-lt-6.0.4.2-43.33.1
      libreoffice-l10n-nb-6.0.4.2-43.33.1
      libreoffice-l10n-nl-6.0.4.2-43.33.1
      libreoffice-l10n-nn-6.0.4.2-43.33.1
      libreoffice-l10n-pl-6.0.4.2-43.33.1
      libreoffice-l10n-pt_BR-6.0.4.2-43.33.1
      libreoffice-l10n-pt_PT-6.0.4.2-43.33.1
      libreoffice-l10n-ro-6.0.4.2-43.33.1
      libreoffice-l10n-ru-6.0.4.2-43.33.1
      libreoffice-l10n-sk-6.0.4.2-43.33.1
      libreoffice-l10n-sv-6.0.4.2-43.33.1
      libreoffice-l10n-uk-6.0.4.2-43.33.1
      libreoffice-l10n-xh-6.0.4.2-43.33.1
      libreoffice-l10n-zh_CN-6.0.4.2-43.33.1
      libreoffice-l10n-zh_TW-6.0.4.2-43.33.1
      libreoffice-l10n-zu-6.0.4.2-43.33.1

   - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 x86_64):

      libreoffice-debuginfo-6.0.4.2-43.33.1
      libreoffice-debugsource-6.0.4.2-43.33.1
      libreoffice-sdk-6.0.4.2-43.33.1
      libreoffice-sdk-debuginfo-6.0.4.2-43.33.1

   - SUSE Linux Enterprise Desktop 12-SP3 (x86_64):

      libreoffice-6.0.4.2-43.33.1
      libreoffice-base-6.0.4.2-43.33.1
      libreoffice-base-debuginfo-6.0.4.2-43.33.1
      libreoffice-base-drivers-mysql-6.0.4.2-43.33.1
      libreoffice-base-drivers-mysql-debuginfo-6.0.4.2-43.33.1
      libreoffice-base-drivers-postgresql-6.0.4.2-43.33.1
      libreoffice-base-drivers-postgresql-debuginfo-6.0.4.2-43.33.1
      libreoffice-calc-6.0.4.2-43.33.1
      libreoffice-calc-debuginfo-6.0.4.2-43.33.1
      libreoffice-calc-extensions-6.0.4.2-43.33.1
      libreoffice-debuginfo-6.0.4.2-43.33.1
      libreoffice-debugsource-6.0.4.2-43.33.1
      libreoffice-draw-6.0.4.2-43.33.1
      libreoffice-draw-debuginfo-6.0.4.2-43.33.1
      libreoffice-filters-optional-6.0.4.2-43.33.1
      libreoffice-gnome-6.0.4.2-43.33.1
      libreoffice-gnome-debuginfo-6.0.4.2-43.33.1
      libreoffice-gtk2-6.0.4.2-43.33.1
      libreoffice-gtk2-debuginfo-6.0.4.2-43.33.1
      libreoffice-impress-6.0.4.2-43.33.1
      libreoffice-impress-debuginfo-6.0.4.2-43.33.1
      libreoffice-mailmerge-6.0.4.2-43.33.1
      libreoffice-math-6.0.4.2-43.33.1
      libreoffice-math-debuginfo-6.0.4.2-43.33.1
      libreoffice-officebean-6.0.4.2-43.33.1
      libreoffice-officebean-debuginfo-6.0.4.2-43.33.1
      libreoffice-pyuno-6.0.4.2-43.33.1
      libreoffice-pyuno-debuginfo-6.0.4.2-43.33.1
      libreoffice-writer-6.0.4.2-43.33.1
      libreoffice-writer-debuginfo-6.0.4.2-43.33.1
      libreoffice-writer-extensions-6.0.4.2-43.33.1

   - SUSE Linux Enterprise Desktop 12-SP3 (noarch):

      libreoffice-branding-upstream-6.0.4.2-43.33.1
      libreoffice-icon-themes-6.0.4.2-43.33.1
      libreoffice-l10n-af-6.0.4.2-43.33.1
      libreoffice-l10n-ar-6.0.4.2-43.33.1
      libreoffice-l10n-ca-6.0.4.2-43.33.1
      libreoffice-l10n-cs-6.0.4.2-43.33.1
      libreoffice-l10n-da-6.0.4.2-43.33.1
      libreoffice-l10n-de-6.0.4.2-43.33.1
      libreoffice-l10n-en-6.0.4.2-43.33.1
      libreoffice-l10n-es-6.0.4.2-43.33.1
      libreoffice-l10n-fi-6.0.4.2-43.33.1
      libreoffice-l10n-fr-6.0.4.2-43.33.1
      libreoffice-l10n-gu-6.0.4.2-43.33.1
      libreoffice-l10n-hi-6.0.4.2-43.33.1
      libreoffice-l10n-hu-6.0.4.2-43.33.1
      libreoffice-l10n-it-6.0.4.2-43.33.1
      libreoffice-l10n-ja-6.0.4.2-43.33.1
      libreoffice-l10n-ko-6.0.4.2-43.33.1
      libreoffice-l10n-nb-6.0.4.2-43.33.1
      libreoffice-l10n-nl-6.0.4.2-43.33.1
      libreoffice-l10n-nn-6.0.4.2-43.33.1
      libreoffice-l10n-pl-6.0.4.2-43.33.1
      libreoffice-l10n-pt_BR-6.0.4.2-43.33.1
      libreoffice-l10n-pt_PT-6.0.4.2-43.33.1
      libreoffice-l10n-ro-6.0.4.2-43.33.1
      libreoffice-l10n-ru-6.0.4.2-43.33.1
      libreoffice-l10n-sk-6.0.4.2-43.33.1
      libreoffice-l10n-sv-6.0.4.2-43.33.1
      libreoffice-l10n-xh-6.0.4.2-43.33.1
      libreoffice-l10n-zh_CN-6.0.4.2-43.33.1
      libreoffice-l10n-zh_TW-6.0.4.2-43.33.1
      libreoffice-l10n-zu-6.0.4.2-43.33.1


References:

   https://www.suse.com/security/cve/CVE-2018-10119.html
   https://www.suse.com/security/cve/CVE-2018-10120.html
   https://bugzilla.suse.com/1089705
   https://bugzilla.suse.com/1089706
   https://bugzilla.suse.com/1090737
   https://bugzilla.suse.com/1091772
   https://bugzilla.suse.com/915996

SUSE: 2018:1296-1 moderate: libreoffice

May 15, 2018
An update that solves two vulnerabilities and has three fixes is now available

Summary

This update for libreoffice to 6.0.4.2 fixes lots of bugs and also the following issues: Security issues fixed: - CVE-2018-10120: The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx did not validate a customizations index, which allowed remote attackers to cause a denial of service (heap-based buffer overflow with write access) or possibly have unspecified other impact via a crafted document that contains a certain Microsoft Word record. (bsc#1089706) - CVE-2018-10119: sot/source/sdstor/stgstrms.cxx used an incorrect integer data type in the StgSmallStrm class, which allowed remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the structured storage ole2 wrapper file format. (bsc#1089705) Other issues fixed: - DOCX import: missing table background color - Bring back offline help per popular demand as lto saves space we could use with it bsc#915996 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP3: zypper in -t patch SUSE-SLE-WE-12-SP3-2018-913=1 - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2018-913=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2018-913=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP3 (x86_64): libreoffice-6.0.4.2-43.33.1 libreoffice-base-6.0.4.2-43.33.1 libreoffice-base-debuginfo-6.0.4.2-43.33.1 libreoffice-base-drivers-mysql-6.0.4.2-43.33.1 libreoffice-base-drivers-mysql-debuginfo-6.0.4.2-43.33.1 libreoffice-base-drivers-postgresql-6.0.4.2-43.33.1 libreoffice-base-drivers-postgresql-debuginfo-6.0.4.2-43.33.1 libreoffice-calc-6.0.4.2-43.33.1 libreoffice-calc-debuginfo-6.0.4.2-43.33.1 libreoffice-calc-extensions-6.0.4.2-43.33.1 libreoffice-debuginfo-6.0.4.2-43.33.1 libreoffice-debugsource-6.0.4.2-43.33.1 libreoffice-draw-6.0.4.2-43.33.1 libreoffice-draw-debuginfo-6.0.4.2-43.33.1 libreoffice-filters-optional-6.0.4.2-43.33.1 libreoffice-gnome-6.0.4.2-43.33.1 libreoffice-gnome-debuginfo-6.0.4.2-43.33.1 libreoffice-gtk2-6.0.4.2-43.33.1 libreoffice-gtk2-debuginfo-6.0.4.2-43.33.1 libreoffice-impress-6.0.4.2-43.33.1 libreoffice-impress-debuginfo-6.0.4.2-43.33.1 libreoffice-mailmerge-6.0.4.2-43.33.1 libreoffice-math-6.0.4.2-43.33.1 libreoffice-math-debuginfo-6.0.4.2-43.33.1 libreoffice-officebean-6.0.4.2-43.33.1 libreoffice-officebean-debuginfo-6.0.4.2-43.33.1 libreoffice-pyuno-6.0.4.2-43.33.1 libreoffice-pyuno-debuginfo-6.0.4.2-43.33.1 libreoffice-writer-6.0.4.2-43.33.1 libreoffice-writer-debuginfo-6.0.4.2-43.33.1 libreoffice-writer-extensions-6.0.4.2-43.33.1 - SUSE Linux Enterprise Workstation Extension 12-SP3 (noarch): libreoffice-branding-upstream-6.0.4.2-43.33.1 libreoffice-icon-themes-6.0.4.2-43.33.1 libreoffice-l10n-af-6.0.4.2-43.33.1 libreoffice-l10n-ar-6.0.4.2-43.33.1 libreoffice-l10n-bg-6.0.4.2-43.33.1 libreoffice-l10n-ca-6.0.4.2-43.33.1 libreoffice-l10n-cs-6.0.4.2-43.33.1 libreoffice-l10n-da-6.0.4.2-43.33.1 libreoffice-l10n-de-6.0.4.2-43.33.1 libreoffice-l10n-en-6.0.4.2-43.33.1 libreoffice-l10n-es-6.0.4.2-43.33.1 libreoffice-l10n-fi-6.0.4.2-43.33.1 libreoffice-l10n-fr-6.0.4.2-43.33.1 libreoffice-l10n-gu-6.0.4.2-43.33.1 libreoffice-l10n-hi-6.0.4.2-43.33.1 libreoffice-l10n-hr-6.0.4.2-43.33.1 libreoffice-l10n-hu-6.0.4.2-43.33.1 libreoffice-l10n-it-6.0.4.2-43.33.1 libreoffice-l10n-ja-6.0.4.2-43.33.1 libreoffice-l10n-ko-6.0.4.2-43.33.1 libreoffice-l10n-lt-6.0.4.2-43.33.1 libreoffice-l10n-nb-6.0.4.2-43.33.1 libreoffice-l10n-nl-6.0.4.2-43.33.1 libreoffice-l10n-nn-6.0.4.2-43.33.1 libreoffice-l10n-pl-6.0.4.2-43.33.1 libreoffice-l10n-pt_BR-6.0.4.2-43.33.1 libreoffice-l10n-pt_PT-6.0.4.2-43.33.1 libreoffice-l10n-ro-6.0.4.2-43.33.1 libreoffice-l10n-ru-6.0.4.2-43.33.1 libreoffice-l10n-sk-6.0.4.2-43.33.1 libreoffice-l10n-sv-6.0.4.2-43.33.1 libreoffice-l10n-uk-6.0.4.2-43.33.1 libreoffice-l10n-xh-6.0.4.2-43.33.1 libreoffice-l10n-zh_CN-6.0.4.2-43.33.1 libreoffice-l10n-zh_TW-6.0.4.2-43.33.1 libreoffice-l10n-zu-6.0.4.2-43.33.1 - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 x86_64): libreoffice-debuginfo-6.0.4.2-43.33.1 libreoffice-debugsource-6.0.4.2-43.33.1 libreoffice-sdk-6.0.4.2-43.33.1 libreoffice-sdk-debuginfo-6.0.4.2-43.33.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): libreoffice-6.0.4.2-43.33.1 libreoffice-base-6.0.4.2-43.33.1 libreoffice-base-debuginfo-6.0.4.2-43.33.1 libreoffice-base-drivers-mysql-6.0.4.2-43.33.1 libreoffice-base-drivers-mysql-debuginfo-6.0.4.2-43.33.1 libreoffice-base-drivers-postgresql-6.0.4.2-43.33.1 libreoffice-base-drivers-postgresql-debuginfo-6.0.4.2-43.33.1 libreoffice-calc-6.0.4.2-43.33.1 libreoffice-calc-debuginfo-6.0.4.2-43.33.1 libreoffice-calc-extensions-6.0.4.2-43.33.1 libreoffice-debuginfo-6.0.4.2-43.33.1 libreoffice-debugsource-6.0.4.2-43.33.1 libreoffice-draw-6.0.4.2-43.33.1 libreoffice-draw-debuginfo-6.0.4.2-43.33.1 libreoffice-filters-optional-6.0.4.2-43.33.1 libreoffice-gnome-6.0.4.2-43.33.1 libreoffice-gnome-debuginfo-6.0.4.2-43.33.1 libreoffice-gtk2-6.0.4.2-43.33.1 libreoffice-gtk2-debuginfo-6.0.4.2-43.33.1 libreoffice-impress-6.0.4.2-43.33.1 libreoffice-impress-debuginfo-6.0.4.2-43.33.1 libreoffice-mailmerge-6.0.4.2-43.33.1 libreoffice-math-6.0.4.2-43.33.1 libreoffice-math-debuginfo-6.0.4.2-43.33.1 libreoffice-officebean-6.0.4.2-43.33.1 libreoffice-officebean-debuginfo-6.0.4.2-43.33.1 libreoffice-pyuno-6.0.4.2-43.33.1 libreoffice-pyuno-debuginfo-6.0.4.2-43.33.1 libreoffice-writer-6.0.4.2-43.33.1 libreoffice-writer-debuginfo-6.0.4.2-43.33.1 libreoffice-writer-extensions-6.0.4.2-43.33.1 - SUSE Linux Enterprise Desktop 12-SP3 (noarch): libreoffice-branding-upstream-6.0.4.2-43.33.1 libreoffice-icon-themes-6.0.4.2-43.33.1 libreoffice-l10n-af-6.0.4.2-43.33.1 libreoffice-l10n-ar-6.0.4.2-43.33.1 libreoffice-l10n-ca-6.0.4.2-43.33.1 libreoffice-l10n-cs-6.0.4.2-43.33.1 libreoffice-l10n-da-6.0.4.2-43.33.1 libreoffice-l10n-de-6.0.4.2-43.33.1 libreoffice-l10n-en-6.0.4.2-43.33.1 libreoffice-l10n-es-6.0.4.2-43.33.1 libreoffice-l10n-fi-6.0.4.2-43.33.1 libreoffice-l10n-fr-6.0.4.2-43.33.1 libreoffice-l10n-gu-6.0.4.2-43.33.1 libreoffice-l10n-hi-6.0.4.2-43.33.1 libreoffice-l10n-hu-6.0.4.2-43.33.1 libreoffice-l10n-it-6.0.4.2-43.33.1 libreoffice-l10n-ja-6.0.4.2-43.33.1 libreoffice-l10n-ko-6.0.4.2-43.33.1 libreoffice-l10n-nb-6.0.4.2-43.33.1 libreoffice-l10n-nl-6.0.4.2-43.33.1 libreoffice-l10n-nn-6.0.4.2-43.33.1 libreoffice-l10n-pl-6.0.4.2-43.33.1 libreoffice-l10n-pt_BR-6.0.4.2-43.33.1 libreoffice-l10n-pt_PT-6.0.4.2-43.33.1 libreoffice-l10n-ro-6.0.4.2-43.33.1 libreoffice-l10n-ru-6.0.4.2-43.33.1 libreoffice-l10n-sk-6.0.4.2-43.33.1 libreoffice-l10n-sv-6.0.4.2-43.33.1 libreoffice-l10n-xh-6.0.4.2-43.33.1 libreoffice-l10n-zh_CN-6.0.4.2-43.33.1 libreoffice-l10n-zh_TW-6.0.4.2-43.33.1 libreoffice-l10n-zu-6.0.4.2-43.33.1

References

#1089705 #1089706 #1090737 #1091772 #915996

Cross- CVE-2018-10119 CVE-2018-10120

Affected Products:

SUSE Linux Enterprise Workstation Extension 12-SP3

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Desktop 12-SP3

https://www.suse.com/security/cve/CVE-2018-10119.html

https://www.suse.com/security/cve/CVE-2018-10120.html

https://bugzilla.suse.com/1089705

https://bugzilla.suse.com/1089706

https://bugzilla.suse.com/1090737

https://bugzilla.suse.com/1091772

https://bugzilla.suse.com/915996

Severity
Announcement ID: SUSE-SU-2018:1296-1
Rating: moderate