Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2024:2258-1 Important: LibreOffice Script Execution Issue

suse
Calendar Grey July 2, 2024
Scroller Suse
Essential LibreOffice upgrade for SUSE to address significant security vulnerabilities and enhance overall system security and reliability.
* bsc#1224279 * bsc#1224309 Cross-References: * CVE-2024-3044

Summary

## This update for libreoffice fixes the following issues: Libreoffice was updated to version 24.2.4.2: * Release notes: * https://wiki.documentfoundation.org/Releases/24.2.1/RC1 * https://wiki.documentfoundation.org/Releases/24.2.1/RC2 * Security issues fixed: * CVE-2024-3044: Fixed unchecked script execution in graphic on-click binding (bsc#1224279) * Other issues fixed: * Fixed LibreOffice build failures with ICU 75 (bsc#1224309) * Updated bundled dependencies: * curl version update from 8.6.0 to 8.7.1 * gpgme version update from 1.20.0 to 1.23.2 * libassuan version update from 2.5.6 to 2.5.7 * libgpg-error version update from 1.47 to 1.48 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

* bsc#1224279

* bsc#1224309

Cross-

* CVE-2024-3044

CVSS scores:

* CVE-2024-3044 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Affected Products:

* SUSE Linux Enterprise High Performance Computing 12 SP5

* SUSE Linux Enterprise Server 12 SP5

* SUSE Linux Enterprise Server for SAP Applications 12 SP5

* SUSE Linux Enterprise Software Development Kit 12 SP5

* SUSE Linux Enterprise Workstation Extension 12 12-SP5

An update that solves one vulnerability and has one security fix can now be

installed.

##

* https://www.suse.com/security/cve/CVE-2024-3044.html

* https://bugzilla.suse.com/show_bug.cgi?id=1224279

* https://bugzilla.suse.com/show_bug.cgi?id=1224309

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:2258-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.