SUSE Security Update: Security update for libreoffice
______________________________________________________________________________

Announcement ID:    SUSE-SU-2020:2283-1
Rating:             moderate
References:         #1062631 #1146025 #1157627 #1165849 #1172053 
                    #1172189 #1172795 #1172796 
Cross-References:   CVE-2020-12802 CVE-2020-12803
Affected Products:
                    SUSE Linux Enterprise Workstation Extension 12-SP5
                    SUSE Linux Enterprise Software Development Kit 12-SP5
______________________________________________________________________________

   An update that solves two vulnerabilities and has 6 fixes
   is now available.

Description:

   This update for libreoffice fixes the following issues:

   - Update to 6.4.5.2:
     * Various fixes all around
   - Remove mime-info and application-registry dirs bsc#1062631
   - Fix bsc#1172053 - LO-L3: Image disappears during roundtrip
     365->Impress->365
     * bsc1172053.diff
   - Fix bsc#1172189 - LO-L3: Impress crashes midway opening a PPTX document
     * bsc1172189.diff
   - Fix bsc#1157627 - LO-L3: Some XML-created shapes simply lost upon PPTX
     import (= earth loses countries)
     * bsc1157627.diff
   - Fix bsc#1146025 - LO-L3: Colored textboxes in PPTX look very odd
     (SmartArt)
   - Fix bsc#1165849 - LO-L3: Shadow size for rectangle is only a fraction of
     Office 365
     * bsc1165849-1.diff
     * bsc1165849-2.diff
     * bsc1165849-3.diff


Patch Instructions:

   To install this SUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Workstation Extension 12-SP5:

      zypper in -t patch SUSE-SLE-WE-12-SP5-2020-2283=1

   - SUSE Linux Enterprise Software Development Kit 12-SP5:

      zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-2283=1



Package List:

   - SUSE Linux Enterprise Workstation Extension 12-SP5 (noarch):

      libreoffice-branding-upstream-6.4.5.2-43.68.1
      libreoffice-icon-themes-6.4.5.2-43.68.1
      libreoffice-l10n-af-6.4.5.2-43.68.1
      libreoffice-l10n-ar-6.4.5.2-43.68.1
      libreoffice-l10n-bg-6.4.5.2-43.68.1
      libreoffice-l10n-ca-6.4.5.2-43.68.1
      libreoffice-l10n-cs-6.4.5.2-43.68.1
      libreoffice-l10n-da-6.4.5.2-43.68.1
      libreoffice-l10n-de-6.4.5.2-43.68.1
      libreoffice-l10n-en-6.4.5.2-43.68.1
      libreoffice-l10n-es-6.4.5.2-43.68.1
      libreoffice-l10n-fi-6.4.5.2-43.68.1
      libreoffice-l10n-fr-6.4.5.2-43.68.1
      libreoffice-l10n-gu-6.4.5.2-43.68.1
      libreoffice-l10n-hi-6.4.5.2-43.68.1
      libreoffice-l10n-hr-6.4.5.2-43.68.1
      libreoffice-l10n-hu-6.4.5.2-43.68.1
      libreoffice-l10n-it-6.4.5.2-43.68.1
      libreoffice-l10n-ja-6.4.5.2-43.68.1
      libreoffice-l10n-ko-6.4.5.2-43.68.1
      libreoffice-l10n-lt-6.4.5.2-43.68.1
      libreoffice-l10n-nb-6.4.5.2-43.68.1
      libreoffice-l10n-nl-6.4.5.2-43.68.1
      libreoffice-l10n-nn-6.4.5.2-43.68.1
      libreoffice-l10n-pl-6.4.5.2-43.68.1
      libreoffice-l10n-pt_BR-6.4.5.2-43.68.1
      libreoffice-l10n-pt_PT-6.4.5.2-43.68.1
      libreoffice-l10n-ro-6.4.5.2-43.68.1
      libreoffice-l10n-ru-6.4.5.2-43.68.1
      libreoffice-l10n-sk-6.4.5.2-43.68.1
      libreoffice-l10n-sv-6.4.5.2-43.68.1
      libreoffice-l10n-uk-6.4.5.2-43.68.1
      libreoffice-l10n-xh-6.4.5.2-43.68.1
      libreoffice-l10n-zh_CN-6.4.5.2-43.68.1
      libreoffice-l10n-zh_TW-6.4.5.2-43.68.1
      libreoffice-l10n-zu-6.4.5.2-43.68.1

   - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64):

      libreoffice-6.4.5.2-43.68.1
      libreoffice-base-6.4.5.2-43.68.1
      libreoffice-base-debuginfo-6.4.5.2-43.68.1
      libreoffice-base-drivers-postgresql-6.4.5.2-43.68.1
      libreoffice-base-drivers-postgresql-debuginfo-6.4.5.2-43.68.1
      libreoffice-calc-6.4.5.2-43.68.1
      libreoffice-calc-debuginfo-6.4.5.2-43.68.1
      libreoffice-calc-extensions-6.4.5.2-43.68.1
      libreoffice-debuginfo-6.4.5.2-43.68.1
      libreoffice-debugsource-6.4.5.2-43.68.1
      libreoffice-draw-6.4.5.2-43.68.1
      libreoffice-draw-debuginfo-6.4.5.2-43.68.1
      libreoffice-filters-optional-6.4.5.2-43.68.1
      libreoffice-gnome-6.4.5.2-43.68.1
      libreoffice-gnome-debuginfo-6.4.5.2-43.68.1
      libreoffice-impress-6.4.5.2-43.68.1
      libreoffice-impress-debuginfo-6.4.5.2-43.68.1
      libreoffice-librelogo-6.4.5.2-43.68.1
      libreoffice-mailmerge-6.4.5.2-43.68.1
      libreoffice-math-6.4.5.2-43.68.1
      libreoffice-math-debuginfo-6.4.5.2-43.68.1
      libreoffice-officebean-6.4.5.2-43.68.1
      libreoffice-officebean-debuginfo-6.4.5.2-43.68.1
      libreoffice-pyuno-6.4.5.2-43.68.1
      libreoffice-pyuno-debuginfo-6.4.5.2-43.68.1
      libreoffice-writer-6.4.5.2-43.68.1
      libreoffice-writer-debuginfo-6.4.5.2-43.68.1
      libreoffice-writer-extensions-6.4.5.2-43.68.1

   - SUSE Linux Enterprise Software Development Kit 12-SP5 (x86_64):

      libreoffice-debuginfo-6.4.5.2-43.68.1
      libreoffice-debugsource-6.4.5.2-43.68.1
      libreoffice-sdk-6.4.5.2-43.68.1
      libreoffice-sdk-debuginfo-6.4.5.2-43.68.1


References:

   https://www.suse.com/security/cve/CVE-2020-12802.html
   https://www.suse.com/security/cve/CVE-2020-12803.html
   https://bugzilla.suse.com/1062631
   https://bugzilla.suse.com/1146025
   https://bugzilla.suse.com/1157627
   https://bugzilla.suse.com/1165849
   https://bugzilla.suse.com/1172053
   https://bugzilla.suse.com/1172189
   https://bugzilla.suse.com/1172795
   https://bugzilla.suse.com/1172796

_______________________________________________
sle-security-updates mailing list
sle-security-updates@lists.suse.com
http://lists.suse.com/mailman/listinfo/sle-security-updates

SUSE: 2020:2283-1 moderate: libreoffice

August 20, 2020
An update that solves two vulnerabilities and has 6 fixes is now available

Summary

This update for libreoffice fixes the following issues: - Update to 6.4.5.2: * Various fixes all around - Remove mime-info and application-registry dirs bsc#1062631 - Fix bsc#1172053 - LO-L3: Image disappears during roundtrip 365->Impress->365 * bsc1172053.diff - Fix bsc#1172189 - LO-L3: Impress crashes midway opening a PPTX document * bsc1172189.diff - Fix bsc#1157627 - LO-L3: Some XML-created shapes simply lost upon PPTX import (= earth loses countries) * bsc1157627.diff - Fix bsc#1146025 - LO-L3: Colored textboxes in PPTX look very odd (SmartArt) - Fix bsc#1165849 - LO-L3: Shadow size for rectangle is only a fraction of Office 365 * bsc1165849-1.diff * bsc1165849-2.diff * bsc1165849-3.diff Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2020-2283=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-2283=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (noarch): libreoffice-branding-upstream-6.4.5.2-43.68.1 libreoffice-icon-themes-6.4.5.2-43.68.1 libreoffice-l10n-af-6.4.5.2-43.68.1 libreoffice-l10n-ar-6.4.5.2-43.68.1 libreoffice-l10n-bg-6.4.5.2-43.68.1 libreoffice-l10n-ca-6.4.5.2-43.68.1 libreoffice-l10n-cs-6.4.5.2-43.68.1 libreoffice-l10n-da-6.4.5.2-43.68.1 libreoffice-l10n-de-6.4.5.2-43.68.1 libreoffice-l10n-en-6.4.5.2-43.68.1 libreoffice-l10n-es-6.4.5.2-43.68.1 libreoffice-l10n-fi-6.4.5.2-43.68.1 libreoffice-l10n-fr-6.4.5.2-43.68.1 libreoffice-l10n-gu-6.4.5.2-43.68.1 libreoffice-l10n-hi-6.4.5.2-43.68.1 libreoffice-l10n-hr-6.4.5.2-43.68.1 libreoffice-l10n-hu-6.4.5.2-43.68.1 libreoffice-l10n-it-6.4.5.2-43.68.1 libreoffice-l10n-ja-6.4.5.2-43.68.1 libreoffice-l10n-ko-6.4.5.2-43.68.1 libreoffice-l10n-lt-6.4.5.2-43.68.1 libreoffice-l10n-nb-6.4.5.2-43.68.1 libreoffice-l10n-nl-6.4.5.2-43.68.1 libreoffice-l10n-nn-6.4.5.2-43.68.1 libreoffice-l10n-pl-6.4.5.2-43.68.1 libreoffice-l10n-pt_BR-6.4.5.2-43.68.1 libreoffice-l10n-pt_PT-6.4.5.2-43.68.1 libreoffice-l10n-ro-6.4.5.2-43.68.1 libreoffice-l10n-ru-6.4.5.2-43.68.1 libreoffice-l10n-sk-6.4.5.2-43.68.1 libreoffice-l10n-sv-6.4.5.2-43.68.1 libreoffice-l10n-uk-6.4.5.2-43.68.1 libreoffice-l10n-xh-6.4.5.2-43.68.1 libreoffice-l10n-zh_CN-6.4.5.2-43.68.1 libreoffice-l10n-zh_TW-6.4.5.2-43.68.1 libreoffice-l10n-zu-6.4.5.2-43.68.1 - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): libreoffice-6.4.5.2-43.68.1 libreoffice-base-6.4.5.2-43.68.1 libreoffice-base-debuginfo-6.4.5.2-43.68.1 libreoffice-base-drivers-postgresql-6.4.5.2-43.68.1 libreoffice-base-drivers-postgresql-debuginfo-6.4.5.2-43.68.1 libreoffice-calc-6.4.5.2-43.68.1 libreoffice-calc-debuginfo-6.4.5.2-43.68.1 libreoffice-calc-extensions-6.4.5.2-43.68.1 libreoffice-debuginfo-6.4.5.2-43.68.1 libreoffice-debugsource-6.4.5.2-43.68.1 libreoffice-draw-6.4.5.2-43.68.1 libreoffice-draw-debuginfo-6.4.5.2-43.68.1 libreoffice-filters-optional-6.4.5.2-43.68.1 libreoffice-gnome-6.4.5.2-43.68.1 libreoffice-gnome-debuginfo-6.4.5.2-43.68.1 libreoffice-impress-6.4.5.2-43.68.1 libreoffice-impress-debuginfo-6.4.5.2-43.68.1 libreoffice-librelogo-6.4.5.2-43.68.1 libreoffice-mailmerge-6.4.5.2-43.68.1 libreoffice-math-6.4.5.2-43.68.1 libreoffice-math-debuginfo-6.4.5.2-43.68.1 libreoffice-officebean-6.4.5.2-43.68.1 libreoffice-officebean-debuginfo-6.4.5.2-43.68.1 libreoffice-pyuno-6.4.5.2-43.68.1 libreoffice-pyuno-debuginfo-6.4.5.2-43.68.1 libreoffice-writer-6.4.5.2-43.68.1 libreoffice-writer-debuginfo-6.4.5.2-43.68.1 libreoffice-writer-extensions-6.4.5.2-43.68.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (x86_64): libreoffice-debuginfo-6.4.5.2-43.68.1 libreoffice-debugsource-6.4.5.2-43.68.1 libreoffice-sdk-6.4.5.2-43.68.1 libreoffice-sdk-debuginfo-6.4.5.2-43.68.1

References

#1062631 #1146025 #1157627 #1165849 #1172053

#1172189 #1172795 #1172796

Cross- CVE-2020-12802 CVE-2020-12803

Affected Products:

SUSE Linux Enterprise Workstation Extension 12-SP5

SUSE Linux Enterprise Software Development Kit 12-SP5

https://www.suse.com/security/cve/CVE-2020-12802.html

https://www.suse.com/security/cve/CVE-2020-12803.html

https://bugzilla.suse.com/1062631

https://bugzilla.suse.com/1146025

https://bugzilla.suse.com/1157627

https://bugzilla.suse.com/1165849

https://bugzilla.suse.com/1172053

https://bugzilla.suse.com/1172189

https://bugzilla.suse.com/1172795

https://bugzilla.suse.com/1172796

Severity
Announcement ID: SUSE-SU-2020:2283-1
Rating: moderate

Related News