Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

SUSE: 2024:2257-1 Important: LibreOffice Script Execution Risk

suse
Calendar Grey July 2, 2024
Dist Suse Esm H88
Debian releases essential security fix for GIMP addressing unverified image handling exploits. Update immediately!
* bsc#1224279 * bsc#1224309 Cross-References: * CVE-2024-3044

Summary

## This update for libreoffice fixes the following issues: Libreoffice was updated to version 24.2.4.2: * Release notes: * https://wiki.documentfoundation.org/Releases/24.2.1/RC1 * https://wiki.documentfoundation.org/Releases/24.2.1/RC2 * Security issues fixed: * CVE-2024-3044: Fixed unchecked script execution in graphic on-click binding (bsc#1224279) * Other issues fixed: * Fixed LibreOffice build failures with ICU 75 (bsc#1224309) * Updated bundled dependencies: * curl version update from 8.6.0 to 8.7.1 * gpgme version update from 1.20.0 to 1.23.2 * libassuan version update from 2.5.6 to 2.5.7 * libgpg-error version update from 1.47 to 1.48 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

* bsc#1224279

* bsc#1224309

Cross-

* CVE-2024-3044

CVSS scores:

* CVE-2024-3044 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Affected Products:

* openSUSE Leap 15.5

* openSUSE Leap 15.6

* SUSE Linux Enterprise Desktop 15 SP5

* SUSE Linux Enterprise Desktop 15 SP6

* SUSE Linux Enterprise High Performance Computing 15 SP5

* SUSE Linux Enterprise Micro 5.5

* SUSE Linux Enterprise Real Time 15 SP5

* SUSE Linux Enterprise Real Time 15 SP6

* SUSE Linux Enterprise Server 15 SP5

* SUSE Linux Enterprise Server 15 SP6

* SUSE Linux Enterprise Server for SAP Applications 15 SP5

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

* SUSE Linux Enterprise Workstation Extension 15 SP5

* SUSE Linux Enterprise Workstation Extension 15 SP6

* SUSE Package Hub 15 15-SP5

* SUSE Package Hub 15 15-SP6

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:2257-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here